Executive brief
A vulnerability in the Prevx security software allows an attacker to remotely shut down critical system processes. By sending a specific command to the software's kernel driver, an attacker can cause a denial of service, potentially disabling security protections or crashing essential applications. This could lead to significant operational downtime and leave the system vulnerable to further attacks.
Technical details
A vulnerability exists in the pxscan.sys driver of Prevx v3.0.5.220 due to improper handling of Input/Output Control (IOCTL) requests. An attacker can send a specially crafted IOCTL code (0x22E044) to the driver to trigger the termination of any processes listed under the registry key HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\pxscan\Files. This is classified as uncontrolled resource consumption (CWE-400). While the attack vector is listed as network-reachable in some metrics, it typically requires the ability to interface with the local driver. Successful exploitation results in a denial of service by killing targeted system or security processes.
Affected products
- Prevx Prevx 3.0.5.220
Timeline
- 2025-08: disclosed: Vulnerability discovered by Dylan Reuter
- 2025-10-28: advisory: CVE-2025-60349 published by NVD