pxscan.sys
The legacy Prevx Scanner driver pxscan.sys 3.0.5.220 processes configurable file targets under its service's Files registry key when IOCTL 0x22E044 is requested. Static analysis confirms that the worker can delete selected files and terminate matching processes from kernel context. The process termination behavior is documented as CVE-2025-60349. The reviewed device uses FILE_DEVICE_SECURE_OPEN and a security descriptor granting full access only to LocalSystem and Builtin Administrators; modifying the service registry configuration also requires appropriate privileges. This is an administrator/SYSTEM-gated BYOVD primitive, not a standard-user privilege escalation. Protected-process termination was not tested locally.
Known samples 1
0 recorded TRUE · 0 recorded FALSE · 1 unknown for loading despite HVCI. Results apply to individual samples.
pxscan.sysSample 1 · HVCI unknown
- MD5
66d4d00c8908888a68b749d91f1e6789- SHA1
d2bdcc6eddeb23af6bf7263c93a1cdef1f0a1f3a- SHA256
b854c4c2c860b8cf00808ba07b9ebbfff66d483b8a2aa15a94211e57b84ee1f2- Imphash
f337527131e256c7ebd56c4389597242- Authentihash MD5
2c46be7fcbc3d20adaa55cd4a7135710- Authentihash SHA1
8d3b12f1c9324b025c1de7aa00844d73a9de7d3e- Authentihash SHA256
6fac3bc346399255c63792f19a2c9b4983b5d4fa3f4da64764870f0f2489d920- Machine
- AMD64
- Version
- 3.0.5.220 built by: WinDDK
- Publisher
- Prevx
Research & references
- https://github.com/magicsword-io/LOLDrivers/issues/429 ↗
- https://github.com/wwwab123/pxscan_ZwDeleteFile_ZwTerminateProcess_BSOD_BYOVD ↗
- https://github.com/djackreuter/CVE-2025-60349 ↗
- https://blog.shellntel.com/p/finding-an-undiscovered-process-termination-vulnerability-in-a-15-year-old-antivirus-driver ↗
- https://www.cve.org/CVERecord?id=CVE-2025-60349 ↗
- https://cveawg.mitre.org/api/cve/CVE-2025-60349 ↗
Acknowledgement: wwwab123, djackreuter (Shellntel) @wwwab123, @djackreuter

