CVE-2025-70795: ProcessMonitorDriver Vulnerability (BYOVD)
Applies to: Safetica Platform | Safetica On-Prem
Devices running Safetica Client for Windows
❗Action required: Microsoft will block older Safetica driver versions
Microsoft has confirmed that older versions of ProcessMonitorDriver.sys will be added to the Windows vulnerable driver blocklist:
- From 15 October 2026: driver version 11.11.4.0 and older
- From 15 November 2026: driver version 11.26.18.0
Once blocked, the driver will not load, and Safetica will stop protecting affected devices entirely. DLP policies, application control and monitoring will all cease to function.
You must update to a version containing driver 11.34.5.0 or newer before these dates. See What you need to do.
Blocking dates are set by Microsoft and are indicative; they may change at Microsoft's discretion.
Summary
|
A vulnerability in Safetica's kernel driver ProcessMonitorDriver.sys allowed process termination via an insufficiently protected IOCTL interface. |
|
|
The vulnerability is being actively abused in the wild via the Bring Your Own Vulnerable Driver (BYOVD) technique, and Microsoft will block affected driver versions in the Windows ecosystem. |
|
|
Yes. Fully remediated in driver 11.34.5.0 or newer (May 2026). The vulnerable functionality has been removed entirely. |
|
|
Update to Safetica Cumulative release 11.30.35 or newer, or Safetica Feature release 11.34.6 or newer. Both contain driver 11.34.5.0. |
|
|
15 October 2026 for driver 11.11.4.0 and older; 15 November 2026 for driver 11.26.18.0. |
|
|
Contact Safetica Support or your Safetica partner as soon as possible so we can discuss your situation directly. |
What is currently happening
This section is updated as the situation develops. The most recent update appears first.
24 July 2026 · Microsoft blocking schedule agreed
Microsoft's Vulnerable Driver Team contacted Safetica in July 2026 regarding the abuse of this driver. We have been working with them through a coordinated process and have agreed the following schedule for adding older driver versions to the Windows vulnerable driver blocklist:
|
Status |
Safetica version |
Driver version |
Microsoft action |
|
Fully vulnerable: |
|
11.11.4.0 and older |
Blocked from 15 October 2026 |
|
Mitigated only: |
|
11.26.18.0 |
Blocked from 15 November 2026 |
|
Fully remediated |
|
11.34.5.0 and newer |
Will not be blocked - confirmed by Microsoft |
Safetica release version and driver version are numbered independently. Always check the driver version when verifying a device.
We requested this timeline specifically to give our customers and partners time to update in an orderly way, rather than facing an immediate block. Once a version is blocked, the driver will not load and Safetica will stop protecting the device entirely.
✍️ All customers should update, regardless of which Windows version they run. The vulnerability itself is what puts your devices at risk. The Microsoft blocklist is only the enforcement consequence.
June 2026 · Active exploitation confirmed in the wild
Security researchers have observed this driver being abused in real-world attacks. ESET has documented its use by The Gentlemen ransomware-as-a-service operation as part of their GentleKiller EDR-killer framework (the "Javelin" variant), which targets several hundred security processes.
In these attacks, the driver is used via the Bring Your Own Vulnerable Driver (BYOVD) technique. This is important to understand: the attacker does not need Safetica to be installed on the target system. They package the vulnerable driver binary into their own tooling and load it on any machine they have already compromised, then use it to terminate antivirus and EDR processes from kernel context - something that is otherwise blocked by tamper protection.
References:
May 2026 · Phase 2: Full remediation
Full remediation is delivered by driver version 11.34.5.0 or newer, contained in the following Safetica releases:
|
Safetica release |
Safetica version |
Driver version |
Released |
|
Safetica On-Prem: Cumulative hotfix release |
11.30.35 |
11.34.5.0 |
June 2026 |
|
Safetica: Feature release |
11.34.6 |
11.34.5.0 |
May 2026 |
Any Safetica release newer than those listed above also contains a fully remediated driver. When verifying a device, the reliable check is the driver version: 11.34.5.0 or higher.
The vulnerable functionality has been removed from the driver entirely. Specifically:
- The IOCTL interface that permitted process termination no longer exists in the driver.
ProcessMonitorDriver.syscontinues to ship as a monitoring-only driver. It observes process activity for application control purposes but has no capability to terminate processes.- Process enforcement has been moved to a separate privileged Windows service that operates outside kernel driver context and does not expose the attack surface described in CVE-2025-70795.
This is an architectural change, not a hardening of the previous interface. The attack surface described in this CVE no longer exists in driver 11.34.5.0 and newer, including when the driver is used in a BYOVD scenario.
Driver details (11.34.5.0)
|
File version |
11.34.5.0 |
|
Internal name |
STProcessMonitor |
|
Compiled |
4 May 2026 |
|
SHA-256 |
|
February 2026 · Phase 1: Initial mitigation
Driver version 11.26.18.0: shipped in Safetica 11.26.19, 11.29.8 and 10.5.150. The driver version prior to this mitigation was 11.11.4.0.
❗ Driver 11.26.18.0 is not the full remediation and will be blocked by Microsoft from 15 November 2026. The information below is retained for reference only - all customers should move to driver 11.34.5.0 or newer.
Our first response was to reduce the attack surface as quickly as possible. This mitigation restricted access to the driver IOCTL interface to the LocalSystem account only, which:
- Prevented access from low-privileged users
- Eliminated the privilege escalation vector
- Reduced the issue to post-exploitation scenarios only, requiring an attacker to have already fully compromised the machine
This mitigation was shared as part of the fix for CVE-2026-0828, which has the same underlying root cause: insufficient access control to the driver IOCTL interface.
Versions containing the Phase 1 mitigation
|
Safetica |
Affected Safetica version |
Affected driver version |
Mitigated from Safetica version |
Mitigated from driver version |
|
Safetica 11: Cumulative release |
< 11.26.19 |
< 11.11.4.0 |
11.26.19 |
11.26.18.0 |
|
Safetica 11: Feature release |
< 11.29.8 |
< 11.11.4.0 |
11.29.8 |
11.26.18.0 |
|
Safetica 10 |
< 10.5.150 |
< 11.11.4.0 |
10.5.150 |
11.26.18.0 |
❗ Phase 1 is no longer sufficient. Any driver version lower than 11.34.5.0 (including 11.26.18.0) will be blocked by Microsoft. Customers on these versions must move to Safetica Cumulative release 11.30.35 or newer, or Safetica Feature release 11.34.6 or newer.
What you need to do
1. Check your current version
Verify the version of ProcessMonitorDriver.sys on your devices (typically located at C:\Program Files\Safetica\ProcessMonitorDriver.sys). Check the File version in the file properties, or review the version reported in your Safetica console.
❗ If the driver version you see is lower than 11.34.5.0, your device is running a vulnerable driver and must be updated. Only driver version 11.34.5.0 or newer contains the full remediation.
2. Update to a fully remediated version
|
Safetica |
Fully remediated from Safetica version |
Driver version |
Released |
|
Safetica On-Prem: Cumulative hotfix release |
11.30.35 |
11.34.5.0 |
June 2026 |
|
Safetica: Feature release |
11.34.6 |
11.34.5.0 |
May 2026 |
Both of these releases (and any newer release) contain driver version 11.34.5.0 or newer, which Microsoft has confirmed will not be blocked.
There are two options for updating:
- We recommend updating via the XML. Learn how to perform the update here.
- To update via the Universal Installer, run the installer, select Manual installation, and choose to install Safetica Management Service.
3. If you cannot update before the deadline
Some organisations (particularly in regulated industries) cannot complete a change management cycle quickly. If this applies to you, contact Safetica Support or your Safetica partner as soon as possible so we can assess your situation and advise on the safest available approach.
❗ We strongly do not recommend disabling or weakening any Windows security features in order to keep an outdated driver running. Doing so exposes your devices to the very class of attack this vulnerability is being used for. Please contact Safetica Support instead of attempting a workaround on your own.
Open a support ticket
Vulnerability overview
A vulnerability was found in the Safetica Client kernel driver ProcessMonitorDriver.sys (internal name STProcessMonitor) that could be abused to perform privileged operations such as process termination via a driver IOCTL interface.
The driver has shipped with our product for approximately 15 years. All versions prior to 11.34.5.0 should be considered affected to some degree.
This issue was disclosed publicly without prior coordination with Safetica; we were not given the opportunity to participate in a responsible disclosure process before the CVE was published.
- CVE: CVE-2025-70795
- Severity (post Phase 1 mitigation): CVSS 3.1: 4.4 (Medium); CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
- Exploitability: Local only
- Privileges required (post Phase 1): LocalSystem
- Affected deployments: Safetica On-Prem and Safetica Platform
- Related CVE: CVE-2026-0828 (same root cause)
What an attacker could achieve
Prior to the Phase 1 mitigation, a low-privileged user could abuse the driver to terminate any process on the system, including kernel-level security processes such as AV, EDR and XDR agents.
After the Phase 1 mitigation, exploitation required LocalSystem privileges, meaning the attacker had to already fully control the machine. At that privilege level the residual capability was limited to terminating tamper-protected security processes from kernel context - which does not provide meaningful additional access to data, but does enable an attacker to blind security tooling before further activity such as ransomware deployment.
After the Phase 2 remediation, this capability has been removed from the driver entirely.
Need help?
If you are unsure which version you are running, cannot complete the update before the blocking dates, or have questions about the impact on your environment:
- Open a support ticket
- Contact your Safetica partner
We are actively contacting partners and enterprise customers directly. If you manage Safetica on behalf of customers, please ensure they are informed of the October and November blocking dates.