PT-2024-14502 · Unknown · Wsftprm.Sys+1
Alex Oudenaarden
+2
·
Published
2024-01-08
·
Updated
2026-02-22
·
CVE-2023-52271
CVSS v3.1
6.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Topaz Antifraud versions prior to 2.0.0.0
Description
The wsftprm.sys kernel driver in Topaz Antifraud allows attackers with limited privileges to terminate any Protected Process Light process through the use of an IOCTL. This allows for the potential silencing of security products like Antivirus and Endpoint Detection and Response (EDR) systems. The issue was observed as early as September 2024 and remains a concern in 2026. Attackers can leverage this by sending a malicious IOCTL to the
ZwTerminateProcess function at the kernel level, effectively removing the security software.Recommendations
Versions prior to 2.0.0.0 should be updated.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Topaz Antifraud
Wsftprm.Sys