PT-2025-32145 · Unknown · Throttlestop.Sys

Anderson Leite

+4

·

Published

2025-08-06

·

Updated

2026-06-15

·

CVE-2025-7771

CVSS v4.0

8.7

High

VectorAV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions ThrottleStop.sys version 3.0.0.0 ThrottleStop.sys (affected versions not specified)
Description The ThrottleStop.sys driver contains an insecure implementation of the MmMapIoSpace() function, which exposes two IOCTL interfaces allowing arbitrary read and write access to physical memory. This allows a local user-mode application to patch the running Windows kernel and invoke arbitrary kernel functions with ring-0 privileges (the highest level of privilege in the Windows architecture). Attackers can use this to execute arbitrary code in the kernel context, leading to privilege escalation and the ability to bypass kernel-level protections or disable security software.
Real-world exploitation has been observed in BYOVD (Bring Your Own Vulnerable Driver) attacks. Malware known as AV Killer and Gentlemen ransomware have used this issue to terminate antivirus and EDR processes, including Windows Defender, CrowdStrike, and BitDefender, to facilitate the deployment of MedusaLocker ransomware. These attacks have specifically targeted organizations in Russia, Belarus, Ukraine, Kazakhstan, and Brazil.
Technical details include the use of IOCTL 0x8000649C to overwrite kernel instructions, such as those in the NtAddAtom() function, with shellcode. The malware may also use the NtQuerySystemInformation() function to identify active security processes.
Recommendations Update ThrottleStop.sys to the latest security update provided by TechPowerUp. Disable public RDP access. Implement multi-factor authentication (MFA). Apply strict access controls and network segmentation.

Exploit

Fix

LPE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-09694
CVE-2025-7771

Affected Products

Throttlestop.Sys