Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2025-61156 — Insecure access control in ThreatFire System Monitor's TfSysMon.sys driver allows unprivileged process termination with kernel privileges, enabling EDR bypass and local DoS. | Kitploit
Tools/GitHubGitHub/d7ead/cve-2025-61156
Privilege EscalationVulnerability AnalysisExploitationIDS/IPS EvasionRed Teaming
GitHubd7ead/cve-2025-61156

CVE-2025-61156

Insecure access control in ThreatFire System Monitor's TfSysMon.sys driver allows unprivileged process termination with kernel privileges, enabling EDR bypass and local DoS.

View Repository
7210 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
Website

CVE-2025-61156

A vulnerability was discovered in the ThreatFire System Monitor (<=v4.7.0.53) kernel-mode TfSysMon.sys component that allows unprivileged users to perform arbitrary process termination with kernel-mode privileges. As a result, PPL and protected system processes can be forcefully stopped, including but not limited to anti-malware, EDR solutions, agentic clients, and so on. This can result in both local EDR Bypass and Denial of Service.

As mentioned above, due to the lack of a proper DACL limiting access to who and who cannot open a HANDLE to this driver, low privileged users including non-Administrators can freely terminate PPL and other protected processes, or cause local denial of service, with kernel privileges via the vulnerable driver.

As of disclosure, this version of the driver does not appear to be included in Microsoft's Blocked Drivers List, and can still be abused by threat actors in BYOVD scenarios. Furthermore, the digital signature on the driver appears to remain valid and unrevoked.

Download Tool