← Back to driver explorer
Driver intelligenceVulnerableVerified

pxscan.sys

The legacy Prevx Scanner driver pxscan.sys 3.0.5.220 processes configurable file targets under its service's Files registry key when IOCTL 0x22E044 is requested. Static analysis confirms that the worker can delete selected files and terminate matching processes from kernel context. The process termination behavior is documented as CVE-2025-60349. The reviewed device uses FILE_DEVICE_SECURE_OPEN and a security descriptor granting full access only to LocalSystem and Builtin Administrators; modifying the service registry configuration also requires appropriate privileges. This is an administrator/SYSTEM-gated BYOVD primitive, not a standard-user privilege escalation. Protected-process termination was not tested locally.

UUID / be1a3216-73db-46e4-b107-87d9b7751181ADDED / 2026-09-18AUTHOR / wwwab123, Michael Haag

Known samples 1

0 recorded TRUE · 0 recorded FALSE · 1 unknown for loading despite HVCI. Results apply to individual samples.

pxscan.sysSample 1 · HVCI unknown
MD5
66d4d00c8908888a68b749d91f1e6789
SHA1
d2bdcc6eddeb23af6bf7263c93a1cdef1f0a1f3a
SHA256
b854c4c2c860b8cf00808ba07b9ebbfff66d483b8a2aa15a94211e57b84ee1f2
Imphash
f337527131e256c7ebd56c4389597242
Authentihash MD5
2c46be7fcbc3d20adaa55cd4a7135710
Authentihash SHA1
8d3b12f1c9324b025c1de7aa00844d73a9de7d3e
Authentihash SHA256
6fac3bc346399255c63792f19a2c9b4983b5d4fa3f4da64764870f0f2489d920
Machine
AMD64
Version
3.0.5.220 built by: WinDDK
Publisher
Prevx

Research & references

Acknowledgement: wwwab123, djackreuter (Shellntel) @wwwab123, @djackreuter