Junglewise Threat Intelligence

CVE-2026-0828: Safetica Endpoint Client process termination via vulnerable IOCTL in ProcessMonitorDriver.sys

CVE-2026-0828 · Severity: info · CVSS 6.8 · Published 2026-06-26

Executive brief

A vulnerability in Safetica's security software allows a standard user to disable critical system processes, including security monitoring tools. Safetica is used by organizations to prevent data leaks and monitor insider risks; an exploit could allow a malicious user or malware to blind the company's security defenses and cause a system-wide denial of service. This effectively bypasses the protection the software is intended to provide.

Technical details

A vulnerability exists in the ProcessMonitorDriver.sys kernel driver of Safetica's endpoint client due to improper input sanitization and lack of user validation in its IOCTL (Input/Output Control) handlers. A local, unprivileged attacker can send specially crafted IOCTL requests to the driver to force the termination of arbitrary, protected system processes. This can be used to disable antivirus (AV), endpoint detection and response (EDR) agents, or the Safetica client itself, leading to a denial of service (DoS) or security bypass. At the time of reporting, no official patch is available, and organizations are advised to use Windows Defender Application Control (WDAC) or AppLocker to restrict access to the driver.

Affected products

  • Safetica Endpoint Client x64 10.5.75.0, 11.11.4.0

Timeline

  • 2025-11-25: other: Vendor notified
  • 2026-01-20: disclosed: Initial disclosure by CERT/CC
  • 2026-06-26: advisory: NVD publication

References