Skip to content
  • There are no suggestions because the search field is empty.

CVE-2025-70795: ProcessMonitorDriver Vulnerability (BYOVD)

Applies to: Safetica Platform | Safetica On-Prem

Devices running Safetica Client for Windows

❗Action required: Microsoft will block older Safetica driver versions

Microsoft has confirmed that older versions of ProcessMonitorDriver.sys will be added to the Windows vulnerable driver blocklist:

  • From 15 October 2026: driver version 11.11.4.0 and older
  • From 15 November 2026: driver version 11.26.18.0

Once blocked, the driver will not load, and Safetica will stop protecting affected devices entirely. DLP policies, application control and monitoring will all cease to function.

You must update to a version containing driver 11.34.5.0 or newer before these dates. See What you need to do.

Blocking dates are set by Microsoft and are indicative; they may change at Microsoft's discretion.

 

Summary

What happened

A vulnerability in Safetica's kernel driver ProcessMonitorDriver.sys allowed process termination via an insufficiently protected IOCTL interface.

Why it matters now

The vulnerability is being actively abused in the wild via the Bring Your Own Vulnerable Driver (BYOVD) technique, and Microsoft will block affected driver versions in the Windows ecosystem.

Is it fixed?

Yes. Fully remediated in driver 11.34.5.0 or newer (May 2026). The vulnerable functionality has been removed entirely.

What you must do

Update to Safetica Cumulative release 11.30.35 or newer, or Safetica Feature release 11.34.6 or newer. Both contain driver 11.34.5.0.

Deadline

15 October 2026 for driver 11.11.4.0 and older; 15 November 2026 for driver 11.26.18.0.

If you cannot update

Contact Safetica Support or your Safetica partner as soon as possible so we can discuss your situation directly.

 

 



What is currently happening

This section is updated as the situation develops. The most recent update appears first.

 

24 July 2026 · Microsoft blocking schedule agreed

Microsoft's Vulnerable Driver Team contacted Safetica in July 2026 regarding the abuse of this driver. We have been working with them through a coordinated process and have agreed the following schedule for adding older driver versions to the Windows vulnerable driver blocklist:

Status

Safetica version

Driver version

Microsoft action

Fully vulnerable:
Exploitable by a low-privileged user

  • Safetica 11 Cumulative<11.26.19

  • Safetica 11 Feature<11.29.8

  • Safetica 10<10.5.150

11.11.4.0 and older

Blocked from 15 October 2026

Mitigated only:
Exploitation restricted to LocalSystem

  • Safetica 11.26.19

  • Safetica 11.29.8

  • Safetica 10.5.150

11.26.18.0

Blocked from 15 November 2026

Fully remediated

  • Cumulative release 11.30.35 or newer

  • Feature release 11.34.6 or newer

11.34.5.0 and newer

Will not be blocked - confirmed by Microsoft

Safetica release version and driver version are numbered independently. Always check the driver version when verifying a device.

We requested this timeline specifically to give our customers and partners time to update in an orderly way, rather than facing an immediate block. Once a version is blocked, the driver will not load and Safetica will stop protecting the device entirely.

✍️ All customers should update, regardless of which Windows version they run. The vulnerability itself is what puts your devices at risk. The Microsoft blocklist is only the enforcement consequence.

 

June 2026 · Active exploitation confirmed in the wild

Security researchers have observed this driver being abused in real-world attacks. ESET has documented its use by The Gentlemen ransomware-as-a-service operation as part of their GentleKiller EDR-killer framework (the "Javelin" variant), which targets several hundred security processes.

In these attacks, the driver is used via the Bring Your Own Vulnerable Driver (BYOVD) technique. This is important to understand: the attacker does not need Safetica to be installed on the target system. They package the vulnerable driver binary into their own tooling and load it on any machine they have already compromised, then use it to terminate antivirus and EDR processes from kernel context - something that is otherwise blocked by tamper protection.

References:

 

May 2026 · Phase 2: Full remediation

Full remediation is delivered by driver version 11.34.5.0 or newer, contained in the following Safetica releases:

Safetica release

Safetica version

Driver version

Released

Safetica On-Prem: Cumulative hotfix release

11.30.35

11.34.5.0

June 2026

Safetica: Feature release

11.34.6

11.34.5.0

May 2026

Any Safetica release newer than those listed above also contains a fully remediated driver. When verifying a device, the reliable check is the driver version: 11.34.5.0 or higher.

The vulnerable functionality has been removed from the driver entirely. Specifically:

    • The IOCTL interface that permitted process termination no longer exists in the driver.
    • ProcessMonitorDriver.sys continues to ship as a monitoring-only driver. It observes process activity for application control purposes but has no capability to terminate processes.
    • Process enforcement has been moved to a separate privileged Windows service that operates outside kernel driver context and does not expose the attack surface described in CVE-2025-70795.

This is an architectural change, not a hardening of the previous interface. The attack surface described in this CVE no longer exists in driver 11.34.5.0 and newer, including when the driver is used in a BYOVD scenario.

Driver details (11.34.5.0)

File version

11.34.5.0

Internal name

STProcessMonitor

Compiled

4 May 2026

SHA-256

ec89766af8640c391382e1d611befdce0e6081e2849e43a462b30c629537ff13

 

February 2026 · Phase 1: Initial mitigation

Driver version 11.26.18.0: shipped in Safetica 11.26.19, 11.29.8 and 10.5.150. The driver version prior to this mitigation was 11.11.4.0.

❗ Driver 11.26.18.0 is not the full remediation and will be blocked by Microsoft from 15 November 2026. The information below is retained for reference only - all customers should move to driver 11.34.5.0 or newer.

Our first response was to reduce the attack surface as quickly as possible. This mitigation restricted access to the driver IOCTL interface to the LocalSystem account only, which:

    • Prevented access from low-privileged users
    • Eliminated the privilege escalation vector
    • Reduced the issue to post-exploitation scenarios only, requiring an attacker to have already fully compromised the machine

This mitigation was shared as part of the fix for CVE-2026-0828, which has the same underlying root cause: insufficient access control to the driver IOCTL interface.

Versions containing the Phase 1 mitigation

Safetica

Affected Safetica version

Affected driver version

Mitigated from Safetica version

Mitigated from driver version

Safetica 11: Cumulative release

< 11.26.19

 < 11.11.4.0

11.26.19

11.26.18.0

Safetica 11: Feature release

< 11.29.8

 < 11.11.4.0

11.29.8

11.26.18.0

Safetica 10

< 10.5.150

 < 11.11.4.0

10.5.150

11.26.18.0

Phase 1 is no longer sufficient. Any driver version lower than 11.34.5.0 (including 11.26.18.0) will be blocked by Microsoft. Customers on these versions must move to Safetica Cumulative release 11.30.35 or newer, or Safetica Feature release 11.34.6 or newer.

 

 



What you need to do

1. Check your current version

Verify the version of ProcessMonitorDriver.sys on your devices (typically located at C:\Program Files\Safetica\ProcessMonitorDriver.sys). Check the File version in the file properties, or review the version reported in your Safetica console.

❗ If the driver version you see is lower than 11.34.5.0, your device is running a vulnerable driver and must be updated. Only driver version 11.34.5.0 or newer contains the full remediation.

 

2. Update to a fully remediated version

Safetica

Fully remediated from Safetica version

Driver version

Released

Safetica On-Prem: Cumulative hotfix release

11.30.35

11.34.5.0

June 2026

Safetica: Feature release

11.34.6

11.34.5.0

May 2026

Both of these releases (and any newer release) contain driver version 11.34.5.0 or newer, which Microsoft has confirmed will not be blocked.

There are two options for updating:

    • We recommend updating via the XML. Learn how to perform the update here.
    • To update via the Universal Installer, run the installer, select Manual installation, and choose to install Safetica Management Service.

 

3. If you cannot update before the deadline

Some organisations (particularly in regulated industries) cannot complete a change management cycle quickly. If this applies to you, contact Safetica Support or your Safetica partner as soon as possible so we can assess your situation and advise on the safest available approach.

❗ We strongly do not recommend disabling or weakening any Windows security features in order to keep an outdated driver running. Doing so exposes your devices to the very class of attack this vulnerability is being used for. Please contact Safetica Support instead of attempting a workaround on your own.

Open a support ticket

 

 


 

Vulnerability overview

A vulnerability was found in the Safetica Client kernel driver ProcessMonitorDriver.sys (internal name STProcessMonitor) that could be abused to perform privileged operations such as process termination via a driver IOCTL interface.

The driver has shipped with our product for approximately 15 years. All versions prior to 11.34.5.0 should be considered affected to some degree.

This issue was disclosed publicly without prior coordination with Safetica; we were not given the opportunity to participate in a responsible disclosure process before the CVE was published.

  • CVE: CVE-2025-70795
  • Severity (post Phase 1 mitigation): CVSS 3.1: 4.4 (Medium); CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H 
  • Exploitability: Local only
  • Privileges required (post Phase 1): LocalSystem
  • Affected deployments: Safetica On-Prem and Safetica Platform
  • Related CVE: CVE-2026-0828 (same root cause)

 

What an attacker could achieve

Prior to the Phase 1 mitigation, a low-privileged user could abuse the driver to terminate any process on the system, including kernel-level security processes such as AV, EDR and XDR agents.

After the Phase 1 mitigation, exploitation required LocalSystem privileges, meaning the attacker had to already fully control the machine. At that privilege level the residual capability was limited to terminating tamper-protected security processes from kernel context - which does not provide meaningful additional access to data, but does enable an attacker to blind security tooling before further activity such as ransomware deployment.

After the Phase 2 remediation, this capability has been removed from the driver entirely.

 

 


Need help?

If you are unsure which version you are running, cannot complete the update before the blocking dates, or have questions about the impact on your environment:

We are actively contacting partners and enterprise customers directly. If you manage Safetica on behalf of customers, please ensure they are informed of the October and November blocking dates.