The legacy Prevx Scanner driver pxscan.sys version 3.0.5.220 exposes kernel-mode file-manipulation and process-termination functionality through IOCTL 0x22E044. Static analysis found that the driver reads configurable targets from its service registry key, then can delete chosen files and terminate matching processes from kernel context. The process-killing capability is tracked as CVE-2025-60349.
An attacker with administrative or LocalSystem privileges could abuse the driver in a bring-your-own-vulnerable-driver (BYOVD) scenario to disable endpoint security processes or remove defensive files. The exposed device is limited to LocalSystem and Builtin Administrators, and modifying the service configuration also requires elevated access; therefore, the flaw is not a direct privilege-escalation route for standard users.

Get the actors, campaigns, and ATT&CK mapping behind it.
1 event from the most recent confirmed update back to the earliest known activity.
The legacy Prevx Scanner driver pxscan.sys version 3.0.5.220 was documented as allowing configurable process termination from kernel context through IOCTL 0x22E044. The behavior can provide a privileged BYOVD primitive for security-tool evasion, but access is restricted to LocalSystem and Builtin Administrators.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.