CVE-2025-7771 Information

Description

ThrottleStop.sys a legitimate driver exposes two IOCTL interfaces that allow arbitrary read and write access to physical memory via the MmMapIoSpace function. This insecure implementation can be exploited by a malicious user-mode application to patch the running Windows kernel and invoke arbitrary kernel functions with ring-0 privileges. The vulnerability enables local attackers to execute arbitrary code in kernel context resulting in privilege escalation and potential follow-on attacks such as disabling security software or bypassing kernel-level protections. ThrottleStop.sys version 3.0.0.0 and possibly others are affected. Apply updates per vendor instructions.

Reference

https://github.com/klsecservices/Advisories/blob/master/K-TechPowerUp-2025-001.md https://securelist.com/av-killer-exploiting-throttlestop-sys/117026/ https://www.techpowerup.com/download/techpowerup-throttlestop/

CNNVD-202508-564 (Published: 2025-08-06)

Share on: