Record summary

CVE-2025-68947 has a selected CVSS score of 5.7 (medium). VulnCheck reports CVE-2025-68947 use in known ransomware campaigns.

Description

NSecsoft 'NSecKrnl' is a Windows driver that allows a local, authenticated attacker to terminate processes owned by other users, including SYSTEM and Protected Processes by issuing crafted IOCTL requests to the driver.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Feb 5, 2026 · VulnCheck
Reported exploitation
Observed · VulnCheck
Ransomware use
Observed · VulnCheck

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 10, 2026 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

Default status: affected

VulnCheck, CVE ListBefore *affected

References

6