The kgameprotect.sys driver (version 2.7.1.7) exposes IOCTL 0x222048 through the \\.\kgameprotect device interface. Its handler accepts a caller-provided process ID, opens that process from kernel mode with PROCESS_TERMINATE access, and calls ZwTerminateProcess, without validating the caller, a registered client, or the target PID.
The flaw could provide a local attacker a means to terminate endpoint-security or other critical user-mode processes, subject to whether unprivileged users can open the device and whether the target is protected by the Windows configuration. The analyzed driver also registers a file-system minifilter, so deployment requires proper minifilter installation; compatibility with Hypervisor-Protected Code Integrity (HVCI) was not established for the sampled version.

Get the actors, campaigns, and ATT&CK mapping behind it.
1 event from the most recent confirmed update back to the earliest known activity.
LOLDrivers added a record for kgameprotect.sys version 2.7.1.7 after identifying IOCTL 0x222048, which opens a caller-selected process with PROCESS_TERMINATE access from kernel mode and calls ZwTerminateProcess without authorization checks. The finding was attributed to Shiroko; review did not confirm unprivileged device access or termination of protected processes across all Windows configurations.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
3 references tracked. Mallory keeps watching after this page renders.
loldrivers.io
Open sourcelearn.microsoft.com
Open sourcelearn.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.