urlexploit
https://github.com/ANYLNK/NSecSoftBYOVD CVE-2025-68947
MEDIUMRansomware
NSecsoft NSecKrnl process termination privilege escalation
Record summary
CVE-2025-68947 has a selected CVSS score of 5.7 (medium). VulnCheck reports CVE-2025-68947 use in known ransomware campaigns.
Description
NSecsoft 'NSecKrnl' is a Windows driver that allows a local, authenticated attacker to terminate processes owned by other users, including SYSTEM and Protected Processes by issuing crafted IOCTL requests to the driver.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Feb 5, 2026 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
- Ransomware use
- Observed · VulnCheck
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 10, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
NSecKrnlBrowse NSecsoft / NSecKrnlDefault status: affected | VulnCheck, CVE List | Before * | affected |
References
6urlexploitTechnical description
https://hexastrike.com/resources/blog/threat-intelligence/valleyrat-exploiting-byovd-to-kill-endpoint-security nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2025-68947 urlGovernment resourceThird-party advisory
https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-013-01.json urlvdb entry
https://www.cve.org/CVERecord?id=CVE-2025-68947 urlTechnical description
https://www.virustotal.com/gui/file/206f27ae820783b7755bca89f83a0fe096dbb510018dd65b63fc80bd20c03261