CVE-2025-1055 is a missing-authorization vulnerability in the K7RKScan kernel driver included in K7 Security Anti-Malware versions before 23.0.0.10. The driver's IOCTL handler permits a local low-privilege user to submit crafted requests that terminate processes running with administrative or SYSTEM privileges, except processes inherently protected by the operating system. Exploitation enables privileged process termination and denial of service. Ransomware operators have abused the vulnerable signed driver in bring-your-own-vulnerable-driver attacks to disable endpoint security software.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a collection of operational Proof-of-Concept (PoC) exploits demonstrating the Bring Your Own Vulnerable Driver (BYOVD) technique to kill protected processes on Windows systems. Each subdirectory targets a specific vulnerable driver, with a Rust-based executable that loads the driver as a service, opens a device handle, and sends a crafted IOCTL to terminate a process by name or PID. The exploits require the vulnerable driver file to be present in the same directory as the executable and are designed for local execution with administrative privileges. The repository covers multiple drivers, including those from Baidu Antivirus (BdApiUtil64.sys, CVE-2024-51324), K7 Ultimate Security (K7RKScan.sys, CVE-2025-52915, CVE-2025-1055), ThreatFire System Monitor (sysmon.sys), Tg Soft (viragt64.sys), and Topaz Antifraud (wsftprm.sys, CVE-2023-52271). The main entry points are the Rust 'main.rs' files in each subdirectory. The exploits are not detection scripts but provide real process termination capability, which can be used to disable AV/EDR or other security software. The code is well-structured, modular, and leverages Windows service and device APIs to interact with the drivers. The attack vector is local, requiring administrative access to load the driver. The endpoints include the driver files and their respective device interfaces (e.g., \\.\BdApiUtil, \\.\ksapi64_dev, etc.). This collection is intended for research and educational purposes to demonstrate the risks of unprotected or vulnerable kernel drivers on Windows platforms.
This repository is a proof-of-concept (PoC) exploit for CVE-2025-1055 and CVE-2025-52915, targeting the K7RKScan.sys Windows kernel driver (version 1516). The exploit consists of a C program (exploit.c) and a README.md with usage instructions. The exploit works by opening a handle to the vulnerable driver (\\.\DosK7RKScnDrv) and repeatedly sending the PID of the Windows Defender process (MsMpEng.exe) via the 0x222018 IOCTL, causing the driver to terminate the process. The README provides instructions for installing the driver and running the exploit. The attack vector is local, requiring the attacker to have the ability to load the vulnerable driver and execute the exploit on the target system. The main fingerprintable endpoints are the device path for the driver, the path to the driver file, and the target process name.
19 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A vulnerability associated with the signed K7RKScan driver that Longlegs abuses in bring-your-own-vulnerable-driver attacks to terminate protected security processes before deploying ransomware. Its use was observed in other recent Longlegs attacks, not confirmed in the detailed critical infrastructure intrusion.
A vulnerability in the K7RKScan.sys driver abused during Warlock's ransomware attacks to disable security software through BYOVD. The content also links prior abuse of the vulnerable driver to DragonForce, but does not describe the underlying technical flaw.
A vulnerability associated with the K7RKScan driver and a bring-your-own-vulnerable-driver technique used to disable antivirus and EDR protections before Warlock ransomware deployment. The reported intrusion deployed the defense-disabling tool to at least 40 hosts. The chronology qualifies identification of the exploited driver and CVE as probable, although the techniques section lists the association without qualification.
A vulnerability in the K7RKScan.sys driver abused in bring-your-own-vulnerable-driver attacks to disable security software. Warlock uses it during ransomware intrusions, and the article also reports previous exploitation of the same driver by DragonForce ransomware actors.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.