4.7
/ 10
MEDIUM
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
Description
NSecsoft 'NSecKrnl' is a Windows driver that allows a local, authenticated attacker to terminate processes owned by other users, including SYSTEM and Protected Processes by issuing crafted IOCTL requests to the driver.
Basic Information
ID
CVE-2025-68947
Source
cisa-cg
Published
Jan 13, 2026 at 21:19
Affected Product
Vendor
NSecsoft
Product
NSecKrnl
Affected Versions
NSecsoft NSecKrnl 0
CWE Classification
References
- www.virustotal.com /gui/file/206f27ae820783b7755bca89f83a0fe096dbb510018dd65b63fc80bd20c03261
- hexastrike.com /resources/blog/threat-intelligence/valleyrat-exploiting-byovd-to-kill-endpoint-security/
- github.com /ANYLNK/NSecSoftBYOVD
- www.cve.org /CVERecord
- raw.githubusercontent.com /cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-013-01.json