NetEase (Hangzhou) Network Co., Ltd NeacSafe64 Driver before version 1.0.0.8 contains a local privilege escalation vulnerability in the NeacSafe64.sys component. According to the provided content, an attacker can send crafted IOCTL requests to the driver to trigger the issue. The vulnerable component is identified as the NeacSafe64.sys driver, also referenced in context as the NeacSafe64 mini-filter driver. The flaw affects versions prior to 1.0.0.8 and exposes privileged kernel-driver functionality to an attacker through insufficiently safe handling of IOCTL commands.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
The repository contains a standalone Windows privilege-escalation implementation attributed by its README to CVE-2025-45737. Its nine files comprise one C++ exploit source, a driver-start batch script, a driver-installation INF, three Visual Studio solution/project files, two Git configuration files, and a short Chinese README. No exploit framework is present. The project targets Visual Studio 2019/v142 and the Windows 10 SDK, with Win32 and x64 configurations, although the exploit uses x64 addresses and fixed kernel structure offsets. The exploit connects to the local minifilter port \OWNeacSafePort using a greeting containing tag 0x4655434B, revision 8, and a hardcoded 32-byte handshake key. Channel methods construct obfuscated messages for kernel-memory read command 14 and write command 70. These interfaces are used to locate the running kernel base, resolve PsInitialSystemProcess from a locally mapped kernel image, read the SYSTEM token, and walk ActiveProcessLinks until the current process is found. It then overwrites that process's token with the SYSTEM token. The fixed offsets are UniqueProcessId 0x440, ActiveProcessLinks 0x448, and Token 0x4B8. Interactive pauses precede the token write and program exit, and registry-access checks provide a before/after demonstration. The INF describes a demand-start filesystem minifilter depending on FltMgr and declares driver version 17.41.6.64 dated December 17, 2021; this metadata does not independently establish the affected-version range. The driver binary and README screenshots are absent. The supplied main.cpp is explicitly truncated, omitting portions of obfuscation, image/module handling, and registry-check implementation, so full compilation and runtime validity cannot be established. Several kernel-memory operation results are unchecked in the visible main routine, and the process-list walk lacks a visible failure bound, creating reliability and crash risks on incompatible systems. No network communication, persistence, exfiltration, or destructive decoy behavior is visible. Repository URL, Git reference, and archive size were not supplied; empty strings and zero represent unavailable metadata.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.