CVE-2025-66680
HIGHWiseCleaner Wise Force Deleter <=7.3.2 - Arbitrary File Deletion
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2025-66680. PoCs published by cwjchoi01.
AI-analyzed exploit summary This repository contains a functional exploit for CVE-2025-66680, which leverages a vulnerable driver in Wise Force Deleter to delete arbitrary files on the system. The exploit bypasses caller process verification and uses DeviceIoControl to send malicious IOCTL requests to the driver.
Description
An issue in the WiseDelfile64.sys component of WiseCleaner Wise Force Deleter 7.3.2 and earlier allows attackers to delete arbitrary files via a crafted request.
Exploits (1)
This repository contains a functional exploit for CVE-2025-66680, which leverages a vulnerable driver in Wise Force Deleter to delete arbitrary files on the system. The exploit bypasses caller process verification and uses DeviceIoControl to send malicious IOCTL requests to the driver.
References (2)
Scores
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H