A Leader in the 2026 Gartner® Magic Quadrant™ for Endpoint Protection. Six years running.Six years. Gartner® Magic Quadrant™ Leader.Find Out Why
Experiencing a Breach?Blog
Get StartedContact Us
SentinelOne
  • Platform
    Platform Overview
    • Singularity Platform
      Welcome to Integrated Enterprise Security
    • AI for Security
      Leading the Way in AI-Powered Security Solutions
    • Securing AI
      Accelerate AI Adoption with Secure AI Tools, Apps, and Agents.
    • How It Works
      The Singularity XDR Difference
    • Singularity Marketplace
      One-Click Integrations to Unlock the Power of XDR
    • Pricing & Packaging
      Comparisons and Guidance at a Glance
    Data & AI
    • Purple AI
      Accelerate SecOps with Generative AI
    • Singularity Hyperautomation
      Easily Automate Security Processes
    • AI-SIEM
      The AI SIEM for the Autonomous SOC
    • AI Data Pipelines
      Security Data Pipeline for AI SIEM and Data Optimization
    • Singularity Data Lake
      AI-Powered, Unified Data Lake
    • Singularity Data Lake for Log Analytics
      Seamlessly Ingest Data from On-Prem, Cloud or Hybrid Environments
    Endpoint Security
    • Singularity Endpoint
      Autonomous Prevention, Detection, and Response
    • Singularity XDR
      Native & Open Protection, Detection, and Response
    • Singularity RemoteOps Forensics
      Orchestrate Forensics at Scale
    • Singularity Threat Intelligence
      Comprehensive Adversary Intelligence
    • Singularity Vulnerability Management
      Application & OS Vulnerability Management
    • Singularity Identity
      Identity Threat Detection and Response
    Cloud Security
    • Singularity Cloud Security
      Block Attacks with an AI-Powered CNAPP
    • Singularity Cloud Native Security
      Secure Cloud and Development Resources
    • Singularity Cloud Workload Security
      Real-Time Cloud Workload Protection Platform
    • Singularity Cloud Data Security
      AI-Powered Threat Detection for Cloud Storage
    • Singularity Cloud Security Posture Management
      Detect and Remediate Cloud Misconfigurations
    Securing AI
    • Prompt Security
      Secure AI Tools Across Your Enterprise
  • Why SentinelOne?
    Why SentinelOne?
    • Why SentinelOne?
      Cybersecurity Built for What’s Next
    • Our Customers
      Trusted by the World’s Leading Enterprises
    • Industry Recognition
      Tested and Proven by the Experts
    • About Us
      The Industry Leader in Autonomous Cybersecurity
    Compare SentinelOne
    • Arctic Wolf
    • Broadcom
    • CrowdStrike
    • Cybereason
    • Microsoft
    • Palo Alto Networks
    • Sophos
    • Splunk
    • Trellix
    • Trend Micro
    • Wiz
    Verticals
    • Energy
    • Federal Government
    • Finance
    • Healthcare
    • Higher Education
    • K-12 Education
    • Manufacturing
    • Retail
    • State and Local Government
  • Services
    Managed Services
    • Managed Services Overview
      Wayfinder Threat Detection & Response
    • Threat Hunting
      World-Class Expertise and Threat Intelligence
    • Managed Detection & Response
      24/7/365 Expert MDR Across Your Entire Environment
    • Incident Readiness & Response
      DFIR, Breach Readiness, & Compromise Assessments
    Support, Deployment, & Health
    • Technical Account Management
      Customer Success with Personalized Service
    • SentinelOne GO
      Guided Onboarding & Deployment Advisory
    • SentinelOne University
      Live and On-Demand Training
    • Services Overview
      Comprehensive Solutions for Seamless Security Operations
    • SentinelOne Community
      Community Login
  • Partners
    Our Network
    • MSSP Partners
      Succeed Faster with SentinelOne
    • Singularity Marketplace
      Extend the Power of S1 Technology
    • Cyber Risk Partners
      Enlist Pro Response and Advisory Teams
    • Technology Alliances
      Integrated, Enterprise-Scale Solutions
    • SentinelOne for AWS
      Hosted in AWS Regions Around the World
    • Channel Partners
      Deliver the Right Solutions, Together
    • SentinelOne for Google Cloud
      Unified, Autonomous Security Giving Defenders the Advantage at Global Scale
    • Partner Locator
      Your Go-to Source for Our Top Partners in Your Region
    Partner Portal→
  • Resources
    Resource Center
    • Case Studies
    • Data Sheets
    • eBooks
    • Reports
    • Videos
    • Webinars
    • Whitepapers
    • Events
    View All Resources→
    Blog
    • Feature Spotlight
    • For CISO/CIO
    • From the Front Lines
    • Identity
    • Cloud
    • macOS
    • SentinelOne Blog
    Blog→
    Tech Resources
    • SentinelLABS
    • Ransomware Anthology
    • Cybersecurity 101
  • About
    About SentinelOne
    • About SentinelOne
      The Industry Leader in Cybersecurity
    • Investor Relations
      Financial Information & Events
    • SentinelLABS
      Threat Research for the Modern Threat Hunter
    • Careers
      The Latest Job Opportunities
    • Press & News
      Company Announcements
    • Cybersecurity Blog
      The Latest Cybersecurity Threats, News, & More
    • FAQ
      Get Answers to Our Most Frequently Asked Questions
    • DataSet
      The Live Data Platform
    • S Foundation
      Securing a Safer Future for All
    • S Ventures
      Investing in the Next Generation of Security, Data and AI
  • Pricing
Get StartedContact Us
CVE Vulnerability Database
Vulnerability Database/CVE-2025-70795

CVE-2025-70795: Safetica STProcessMonitor DOS Vulnerability

CVE-2025-70795 is a denial of service vulnerability in Safetica STProcessMonitor 11.11.4.0 that allows unauthorized process termination through crafted IOCTL requests. This article covers technical details, impact, and mitigation.

Published: April 23, 2026

CVE-2025-70795 Overview

A driver vulnerability exists in STProcessMonitor 11.11.4.0, part of the Safetica Application suite, that allows privileged users to send crafted IOCTL requests to terminate processes protected by third-party implementations. This vulnerability stems from insufficient caller validation in the driver's IOCTL handler, enabling unauthorized processes to perform kernel-space operations that can disrupt critical services.

Critical Impact

Successful exploitation enables denial of service attacks by allowing unauthorized process termination of protected third-party services and applications through kernel-level driver manipulation.

Affected Products

  • STProcessMonitor 11.11.4.0
  • Safetica Application Suite (containing vulnerable driver)

Discovery Timeline

  • 2026-04-17 - CVE CVE-2025-70795 published to NVD
  • 2026-04-17 - Last updated in NVD database

Technical Details for CVE-2025-70795

Vulnerability Analysis

This vulnerability is classified under CWE-269 (Improper Privilege Management) and represents a driver-level security flaw in the STProcessMonitor component. The core issue lies in the IOCTL handler's failure to properly validate the identity and privileges of calling processes before executing sensitive kernel-space operations.

When unauthorized processes load the vulnerable driver, they can send a specially crafted IOCTL request using the control code 0xB822200C. Due to the absence of proper caller validation, the driver accepts and processes this request, allowing the attacker to terminate processes that are supposed to be protected by third-party security implementations.

The local attack vector requires an attacker to have existing access to the target system. Once local access is obtained, exploitation can be achieved with low complexity and without requiring user interaction.

Root Cause

The root cause of CVE-2025-70795 is insufficient caller validation in the driver's IOCTL handler routine. The STProcessMonitor.sys driver fails to verify whether the process sending IOCTL requests has legitimate authorization to perform protected operations. This missing validation allows any local process with sufficient privileges to load the driver and issue commands that should be restricted to authorized Safetica components only.

This type of vulnerability is commonly observed in "Living off the Land Drivers" (LOLDrivers), where legitimate signed drivers contain security weaknesses that can be exploited by attackers to perform malicious actions while bypassing security controls.

Attack Vector

The attack leverages the local system access to interact with the vulnerable kernel driver. An attacker with local privileges can:

  1. Load the STProcessMonitor.sys driver into the kernel
  2. Open a handle to the driver device object
  3. Send a crafted IOCTL request with control code 0xB822200C
  4. Specify the process ID of a protected target process
  5. Trigger the driver to terminate the specified process, bypassing third-party protection mechanisms

The exploitation requires crafting an IOCTL request with the specific control code 0xB822200C that targets the vulnerable handler. Since the driver operates in kernel space, successful exploitation allows the attacker to terminate processes that would otherwise be protected by security software or other third-party implementations.

Detection Methods for CVE-2025-70795

Indicators of Compromise

  • Unexpected loading of STProcessMonitor.sys driver outside normal Safetica application operations
  • Process termination events affecting security software or protected services without corresponding application errors
  • IOCTL requests to STProcessMonitor driver from processes not associated with Safetica software
  • Anomalous driver load events followed immediately by protected process termination

Detection Strategies

  • Monitor for driver load events involving STProcessMonitor.sys from unexpected parent processes or locations
  • Implement driver signing verification and allowlisting to detect unauthorized use of the vulnerable driver
  • Deploy endpoint detection rules for IOCTL calls to STProcessMonitor devices from non-Safetica processes
  • Use behavioral analytics to correlate driver loads with subsequent unexpected process termination events

Monitoring Recommendations

  • Enable Windows kernel auditing to capture driver load events and IOCTL communications
  • Configure SentinelOne to monitor for suspicious driver activity and process termination patterns
  • Establish baseline behavior for Safetica components to identify anomalous driver interactions
  • Review VirusTotal analysis reports for driver file hashes to identify known vulnerable versions

How to Mitigate CVE-2025-70795

Immediate Actions Required

  • Audit systems for the presence of STProcessMonitor version 11.11.4.0 and remove or restrict access to the vulnerable driver
  • Implement application control policies to prevent unauthorized loading of the vulnerable driver
  • Monitor for exploitation attempts using endpoint detection and response tools
  • Review and restrict local administrative privileges to minimize the attack surface

Patch Information

Organizations should contact Safetica for updated versions of the STProcessMonitor driver that include proper caller validation in the IOCTL handler. Review the GitHub LOLDrivers Issue #268 and the LOLDrivers commit for additional technical details and community tracking of this vulnerability.

Additional analysis of the vulnerable driver files is available through VirusTotal: File Analysis #70bcec00, File Analysis #9ace6a1e, and File Analysis #fc358848.

Workarounds

  • Block or remove the vulnerable STProcessMonitor.sys driver from systems where Safetica functionality is not required
  • Implement Windows Defender Application Control (WDAC) or similar policies to restrict driver loading to authorized binaries
  • Use driver blocklist capabilities in endpoint security solutions to prevent the vulnerable driver from loading
  • Restrict local administrator access to limit the ability to load kernel drivers

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

  • Vulnerability Details
  • TypeDOS

  • Vendor/TechSafetica

  • SeverityMEDIUM

  • CVSS Score5.5

  • EPSS Probability0.01%

  • Known ExploitedNo
  • CVSS Vector
  • CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
  • Impact Assessment
  • ConfidentialityLow
  • IntegrityNone
  • AvailabilityHigh
  • CWE References
  • CWE-269
  • Technical References
  • Kafan Forum Thread Part 1

  • Kafan Forum Thread Part 2

  • GitHub LOLDrivers Commit

  • GitHub LOLDrivers Issue #268

  • VirusTotal File Analysis #70bcec00

  • VirusTotal File Analysis #9ace6a1e

  • VirusTotal File Analysis #fc358848
  • Latest CVEs
  • CVE-2026-9813: FlowIntel SSRF Vulnerability

  • CVE-2026-4377: D-Link DWR-X1820 Auth Bypass Vulnerability

  • CVE-2026-47074: ex_aws_sns Auth Bypass Vulnerability

  • CVE-2026-46241: Linux Kernel Use-After-Free Vulnerability
Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.

Try SentinelOne
  • Get Started
  • Get a Demo
  • Product Tour
  • Why SentinelOne
  • Pricing & Packaging
  • FAQ
  • Contact
  • Contact Us
  • Customer Support
  • SentinelOne Status
  • Language
  • Platform
  • Singularity Platform
  • Singularity Endpoint
  • Singularity Cloud
  • Singularity AI-SIEM
  • Singularity Identity
  • Singularity Marketplace
  • Purple AI
  • Services
  • Wayfinder TDR
  • SentinelOne GO
  • Technical Account Management
  • Support Services
  • Verticals
  • Energy
  • Federal Government
  • Finance
  • Healthcare
  • Higher Education
  • K-12 Education
  • Manufacturing
  • Retail
  • State and Local Government
  • Cybersecurity for SMB
  • Resources
  • Blog
  • Labs
  • Case Studies
  • Videos
  • Product Tours
  • Events
  • Cybersecurity 101
  • eBooks
  • Webinars
  • Whitepapers
  • Press
  • News
  • Ransomware Anthology
  • Company
  • About Us
  • Our Customers
  • Careers
  • Partners
  • Legal & Compliance
  • Security & Compliance
  • Investor Relations
  • S Foundation
  • S Ventures

©2026 SentinelOne, All Rights Reserved.

Privacy Notice Terms of Use

English