CVE-2025-51619: Thesycon DPC Latency Checker driver vulnerability

Published Sep 9, 2026
·
Updated

A vulnerability in the Thesycon DPC Latency Checker driver (dpc.sys) thru 1.4.0 allows local unprivileged users to cause a denial-of-service (BSOD) condition on Windows systems. The driver exposes an IOCTL interface (0x81772008) that accepts user-controlled input without validating pointers before passing them to kernel APIs. Specifically, it dereferences a user-supplied pointer and uses the resulting value in a call to ExSetTimerResolution, leading to an arbitrary kernel memory access. Exploiting this flaw results in a system crash.

Affected Software

1 affected component
Thesycon DPC Latency Checker driver<=1.4.0

Event History

Sep 9, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description

Frequently Asked Questions

1

Who can trigger the denial of service?

A local unprivileged user can trigger the flaw. Remote exploitation is not described in the available information.

2

What does an attacker need to exploit it?

The attacker needs local access to a Windows system with the affected dpc.sys driver installed and access to its IOCTL interface. Exploitation involves sending controlled input to IOCTL 0x81772008.

3

How can defenders determine whether a system may be affected?

Check whether the Thesycon DPC Latency Checker driver dpc.sys is installed and whether its version is 1.4.0 or earlier. Systems without this driver are not indicated as affected by the provided information.

4

What is the impact of successful exploitation?

Successful exploitation causes a Windows blue-screen crash, resulting in denial of service. The provided information does not describe code execution, privilege escalation, or data disclosure.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203