CVE-2025-60349: High severity Prevx Prevx vulnerability
An issue was discovered in Prevx v3.0.5.220 allowing attackers to cause a denial of service via sending IOCTL code 0x22E044 to the pxscan.sys driver. Any processes listed under registry key HKEYLOCALMACHINE\System\CurrentControlSet\Services\pxscan\Files will be terminated.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-60349?
CVE-2025-60349 is classified as a medium severity vulnerability due to its potential to cause a denial of service.
How do I fix CVE-2025-60349?
To mitigate CVE-2025-60349, you should update to the latest version of Prevx that addresses this issue.
Which systems are affected by CVE-2025-60349?
CVE-2025-60349 affects Prevx version 3.0.5.220 and potentially earlier versions that utilize the pxscan.sys driver.
What impact does CVE-2025-60349 have on systems?
CVE-2025-60349 allows attackers to terminate processes listed under the registry key HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\pxscan\Files.
Is CVE-2025-60349 easy to exploit?
Exploiting CVE-2025-60349 requires sending a specific IOCTL code, which may be achievable by an attacker with sufficient access.