CVE-2025-7771General

LOWCVSS 8.7 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

ThrottleStop.sys, a legitimate driver, exposes two IOCTL interfaces that allow arbitrary read and write access to physical memory via the MmMapIoSpace function. This insecure implementation can be exploited by a malicious user-mode application to patch the running Windows kernel and invoke arbitrary kernel functions with ring-0 privileges. The vulnerability enables local attackers to execute arbitrary code in kernel context, resulting in privilege escalation and potential follow-on attacks, such as disabling security software or bypassing kernel-level protections. ThrottleStop.sys version 3.0.0.0 and possibly others are affected. Apply updates per vendor instructions.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-782

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Public PoC and exploit tooling are both present
  • 5 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 2 signals
  • General: 3 classified signals
  • Peaked 1d ago at 2 mentions (2026-06-08); latest day: 1
  • 5 total mentions across 4 days

Deep dive

Activity timeline5 mentions / 4d
01122Mentions · 2026-02-04: 1Mentions · 2026-05-14: 1Mentions · 2026-06-08: 2Mentions · 2026-06-10: 1PoC Mentioned / Linked · 2026-02-04: 1PoC Mentioned / Linked · 2026-06-08: 1Exploit Tool / Code · 2026-02-04: 1Exploit Tool / Code · 2026-06-08: 102-0405-1406-0806-10
Signal classification3 categories
General
360.0%
Exploit
120.0%
PoC
120.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-02-041
Exploit1
2026-05-141
General1
2026-06-082
General1PoC1
2026-06-101
General1
Full discourse5 posts
  • OS Dev@OSdev_
    PoC

    Interesting read on MmIoSpaceEx() - windows kernel Method to map device registers into virtual kernel space. https://github.com/D4rkks/CVE-2025-7771-Vulnerability-Exploration

    Post summary

    The content points to a GitHub repository that hosts code and analysis for CVE‑2025‑7771, suggesting a proof‑of‑concept exists, but provides no evidence of active exploitation, patches, or technical specifics.

    225078424.5K
    4.7K followersView on X
  • Syed Wajeeh@SyedWaj25802383
    Exploit

    Game over for Windows? 🏛️♟️ 0xKern3lCrush checkmates the "Trust" model. BYOVD makes PPL a joke. Documenting how Safetica (CVE-2026-0828) & ThrottleStop (CVE-2025-7771) become kernel sledgehammers. 0xArtifacts: 👉 https://github.com/DeathShotXD/0xKern3lCrush-Foreverday-BYOVD-CVE-2026-0828 #InfoSec #BYOVD #redteam #EthicalHacking https://t.co/740P4RGdhm

    Post summary

    The tweet shares a GitHub repository that appears to provide exploit code for Safetica (CVE‑2026‑0828) and ThrottleStop (CVE‑2025‑7771), demonstrating how these vulnerabilities can be leveraged as kernel-level exploits.

    01020130
    13 followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2026-23111 2 - CVE-2026-23479 3 - CVE-2026-42271 4 - CVE-2025-7771 5 - CVE-2026-6973 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The post lists the top five trending CVEs without providing further details or context.

    00010121
    1.7K followersView on X
  • OS Dev@OSdev_
    General

    For detail explanation: https://securelist.com/av-killer-exploiting-throttlestop-sys/117026/ CVE details : https://www.cve.org/CVERecord?id=CVE-2025-7771

    Post summary

    The post only references an article and a CVE record without providing further details.

    00010314
    3.3K followersView on X
  • Bhaskar kannan@BhaskarKanan
    General

    @ctrlaltintel @ctrlaltintel : Add this CVE-2025-7771 as well.. It is linked with Gentleman RaaS #Ransomware #APT #Malware #Cybersecurity

    Post summary

    The tweet simply references CVE-2025-7771 and notes its association with Gentleman ransomware, without providing further details or actionable information.

    000001.5K
    128 followersView on X

Explore more