CVE-2025-7771
ThrottleStop.sys, a legitimate driver, exposes two IOCTL interfaces that allow arbitrary read and write access to physical memory via the MmMapIoSpace function. This insecure implementation can be exploited by a malicious user-mode application to patch the running Windows kernel and invoke arbitrary kernel functions with ring-0 privileges. The vulnerability enables local attackers to execute arbitrary code in kernel context, resulting in privilege escalation and potential follow-on attacks, such as disabling security software or bypassing kernel-level protections. ThrottleStop.sys version 3.0.0.0 and possibly others are affected. Apply updates per vendor instructions.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.7
- CVSS vector
- CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
- EPSS probability
- 6.83%
- CWE
- CWE-782
- Published
- 2025-08-06
- Last modified
- 2026-03-12
Affected products
- TechPowerUp ThrottleStop
Weakness type
Related vulnerabilities
- CVE-2026-16003 — Exposed IOCTL with Insufficient Access Control in Armoury Crate driver allows a local user to add...
- CVE-2026-16004 — Exposed IOCTL with Insufficient Access Control in Armoury Crate driver allows a local user to read...
- CVE-2026-75809 — Exposed IOCTL with insufficient access control in ASUS Armoury Crate allows a local user to...
- CVE-2026-80117 — PassMark PerformanceTest, BurnInTest, and OSForensics Arbitrary I/O Port Access via DirectIo64.sys
- CVE-2026-80116 — PassMark PerformanceTest, BurnInTest, and OSForensics Privilege Escalation via DirectIo64.sys IOCTL
- CVE-2026-80115 — PassMark PerformanceTest, BurnInTest, and OSForensics Kernel Crash via DirectIo64.sys MSR Write IOCTL
- CVE-2026-80113 — PassMark PerformanceTest, BurnInTest, and OSForensics Arbitrary Bit Clear via DirectIo64.sys IOCTL
- CVE-2019-25764 — **UNSUPPORTED WHEN ASSIGNED** Exposed IOCTL with Insufficient Access Control in the ASUS AURA SYNC...