CVE-2025-70795 affects STProcessMonitor 11.11.4.0, a component of the Safetica Application suite. The vulnerability is in the driver's IOCTL handler, which performs insufficient validation of the calling process before honoring a crafted IOCTL request. An admin-privileged user can load or access the driver and send IOCTL 0xB822200C to trigger termination of processes that are otherwise protected through a third-party implementation. Because the operation is performed in kernel space without proper caller authorization checks, unauthorized processes can invoke privileged termination functionality against protected targets.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
Repository purpose/structure: - Visual Studio C++ solution implementing a local Windows BYOVD-style utility named STProcessMonitorBYOVD. - Core files: - STProcessMonitorBYOVD/Main.cpp: CLI entry point implementing driver load/unload and process termination actions. - STProcessMonitorBYOVD/Service.cpp: helper routines to create/start/stop/delete a kernel driver service via SCM. - STProcessMonitorBYOVD/FindProcess.cpp: enumerates processes via Toolhelp32 to resolve PIDs by process name. - STProcessMonitorBYOVD/TokenAdjust.cpp: enables SeDebugPrivilege (and SeTcbPrivilege, though unused in Main.cpp) for token/process access. - STProcessMonitorBYOVD/Struct.h + Functions.h: shared declarations. - Project includes two driver binaries as non-code artifacts: STProcessMonitor.sys and STProcessMonitorNew.sys. Exploit capabilities (what it actually does): - Driver installation (local): /Init computes the driver path as <exe_dir>\\STProcessMonitor.sys and installs it as a demand-start kernel driver service named "STProcessMonitor" using CreateServiceW + StartService. - Driver removal: /Uninst stops and deletes the service. - Arbitrary process termination via driver IOCTLs: - /Kill <names...>: opens device \\.\STProcessMonitorDriver and for each provided process name, finds all matching PIDs and sends IOCTL 0xB822200C with a TerminateProcessInfo{ProcessId=<pid>} buffer. - /Terminate <names...>: if already running as SYSTEM, performs the same PID-by-name loop but uses IOCTL 0xB822A00C. - Self-elevation to SYSTEM (local token theft): if not SYSTEM in /Terminate mode, it enables SeDebugPrivilege, locates a SYSTEM-owned winlogon.exe instance, duplicates its token (DuplicateTokenEx) and relaunches the current command line with CreateProcessWithTokenW to obtain a SYSTEM process, then expects the user to re-run/continue under SYSTEM. Notable targeting indicators: - README claims relation to CVE-2025-70795 and CVE-2026-0828, but the code itself is a generic BYOVD driver-control utility: it relies on a bundled driver exposing a known device name and IOCTLs to terminate processes. Network activity: - None in code. No HTTP/DNS/IP endpoints; all interaction is local (SCM + device IOCTL + process/token APIs).
Repository purpose: a Windows C++ console tool demonstrating BYOVD (Bring Your Own Vulnerable Driver) abuse of the STProcessMonitor driver to terminate arbitrary processes, referencing CVE-2025-70795. It supports loading/unloading the driver as a kernel service and sending crafted IOCTLs to the driver’s device object to kill processes by PID resolved from process names. Key capabilities (from Main.cpp and helpers): - Driver service management: /Init creates a SERVICE_KERNEL_DRIVER service named "STProcessMonitor" pointing to a driver file expected next to the EXE ("\STProcessMonitor.sys"), then starts it (Service.cpp). /Uninst stops and deletes the service. - Process discovery: FindProcess.cpp enumerates processes via Toolhelp32 snapshot and returns all PIDs matching a provided executable name (case-insensitive). - Process termination via driver IOCTL: - /Kill <names...>: opens the device "\\.\STProcessMonitorDriver" and for each matching PID sends DeviceIoControl with code 0xB822200C and a small input struct containing the PID handle. README claims this path works “without any privilege” with driver version 11.11.4.0 (CVE-2025-70795). - /Terminate <names...>: intended for an updated driver (README mentions 11.26.18) that checks the caller is NT AUTHORITY\SYSTEM. The program first checks if it is already SYSTEM; if yes, it sends IOCTL 0xB822A00C to terminate processes. - Local privilege escalation to SYSTEM (to satisfy updated driver checks): if not SYSTEM, the tool enables SeDebugPrivilege, locates a SYSTEM-owned winlogon.exe, duplicates its token (DuplicateTokenEx), and relaunches itself with CreateProcessWithTokenW using the same command line. This is a token-theft style elevation that typically requires Administrator/SeDebugPrivilege. Repository structure: - STProcessMonitorBYOVD/Main.cpp: primary entry point implementing CLI parsing and the IOCTL abuse + SYSTEM relaunch logic. - STProcessMonitorBYOVD/Service.cpp: SCM routines to create/start/stop/delete the kernel driver service. - STProcessMonitorBYOVD/FindProcess.cpp: PID lookup by process name. - STProcessMonitorBYOVD/TokenAdjust.cpp: privilege enabling helpers (SeDebugPrivilege, SeTcbPrivilege though SeTcb is not used in Main.cpp). - STProcessMonitorBYOVD/Struct.h + Functions.h: shared declarations. - Visual Studio solution/project files; project references two driver binaries (STProcessMonitor.sys and STProcessMonitorNew.sys), though the runtime path in code expects STProcessMonitor.sys in the EXE directory. Overall, this is a local Windows BYOVD exploit utility (not a network exploit) focused on abusing a vulnerable/abusable driver interface to terminate protected processes, with an added SYSTEM token duplication step for newer driver versions that restrict IOCTL callers.
4 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.