Skip to content

Add STProcessMonitor Driver #268

@wwwab123

Description

@wwwab123

CVE-2025-70795 vulnerability in STProcessMonitor Driver from Safetica

  • Affects:
    • Legacy builds (11.11.4.0+) -> low-privilege BYOVD abuse
    • Current build (11.26.18.0+) -> LocalSystem-privilege BYOVD abuse

Driver hashes:

  • STProcessMonitor.sys 11.11.4.0 SHA256: 70bcec00c215fe52779700f74e9bd669ff836f594df92381cbfb7ee0568e7a8b

STProcessMonitor.zip

Image

Poc see: https://github.com/wwwab123/BYOVD/tree/main/STProcessMonitor114-Killer

  • STProcessMonitor.sys 11.26.18.0 SHA256: 5b4f59236a9b950bcd5191b35d19125f60cfb9e1a1e1aa2e4f914b6745dde9df

STProcessMonitor.zip

Poc (need LocalSystem-privilege) see: https://github.com/wwwab123/BYOVD/tree/main/STProcessMonitor2618-Killer

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions