
Insecure access control in ThreatFire System Monitor's TfSysMon.sys driver allows unprivileged process termination with kernel privileges, enabling EDR bypass and local DoS.
A vulnerability was discovered in the ThreatFire System Monitor (<=v4.7.0.53) kernel-mode TfSysMon.sys component that allows unprivileged users to perform arbitrary process termination with kernel-mode privileges. As a result, PPL and protected system processes can be forcefully stopped, including but not limited to anti-malware, EDR solutions, agentic clients, and so on. This can result in both local EDR Bypass and Denial of Service.
As mentioned above, due to the lack of a proper DACL limiting access to who and who cannot open a HANDLE to this driver, low privileged users including non-Administrators can freely terminate PPL and other protected processes, or cause local denial of service, with kernel privileges via the vulnerable driver.
As of disclosure, this version of the driver does not appear to be included in Microsoft's Blocked Drivers List, and can still be abused by threat actors in BYOVD scenarios. Furthermore, the digital signature on the driver appears to remain valid and unrevoked.