Description
NSecsoft 'NSecKrnl' is a Windows driver that allows a local, authenticated attacker to terminate processes owned by other users, including SYSTEM and Protected Processes by issuing crafted IOCTL requests to the driver.
Problem types
Product status
Any version before *
Credits
Maurice Fielenbach, Hexastrike Cybersecurity
References
www.virustotal.com/...3a0fe096dbb510018dd65b63fc80bd20c03261 (url)
hexastrike.com/...xploiting-byovd-to-kill-endpoint-security/ (url)
github.com/ANYLNK/NSecSoftBYOVD (url)
www.cve.org/CVERecord?id=CVE-2025-68947 (url)
raw.githubusercontent.com/...IT/white/2026/va-26-013-01.json (url)