EDR process termination via exposed IOCTL
Published Aug 1, 2025 · Updated Aug 1, 2025
Insufficient IOCTL access control in Hangzhou Shunwang Rentdrv2 before 2024-12-24 allows local users to terminate EDR processes. The driver's 0x22E010 dispatch path accepts a caller-supplied PID, opens that process with ZwOpenProcess, and ends it with ZwTerminateProcess. Administrative privileges are required to load or access the driver; successful abuse disables a selected security process, while other impact remains unspecified.
Summary
What happened
Insufficient IOCTL access control in Hangzhou Shunwang Rentdrv2 before 2024-12-24 allows local users to terminate EDR processes. The driver's 0x22E010 dispatch path accepts a caller-supplied PID, opens that process with ZwOpenProcess, and ends it with ZwTerminateProcess. Administrative privileges are required to load or access the driver; successful abuse disables a selected security process, while other impact remains unspecified.
The record
- CVE
- CVE-2023-44976
- Published
- Aug 1, 2025
- Updated
- Aug 1, 2025
- Vendor
- Hangzhou Shunwang Technology Co., Ltd.
- Product
- Rentdrv2
- Classifications
- CWE-782, T1562.001
- Attack vector
- local
- Privileges
- admin
Timeline
How it unfolded
- Aug 1, 2025CVE publishedPublication date reported by the CVE source.
- Aug 1, 2025Record updatedLatest update available in the CVE record.
Exploitability
Present is not the same as exploitable
Compare your product and version with the public record. A matching version still requires validation against your environment.
Is a vulnerable build present?
Compare these published version ranges with your installed build and any vendor patches.
- Affected versionversion=1aed62a63b4802e599bbd33162319129501d603cceeb5e1eb22fd4733b3018a3
- Affected versionversion=9165d4f3036919a96b86d24b64d75d692802c7513f2b3054b20be40c212240a5
What conditions does exploitation require?
What is affected?
Published CVSS scores
CVSS describes severity. EPSS estimates exploitation probability.
Attacks
What attackers are doing with it
Daily unique IPs observed by Shadowserver honeypots for known exploited vulnerabilities (KEVs). Missing observations do not establish an absence of attacks.
Weakness, pattern, technique
Public exploit references
- BadRentdrv2 proof of conceptfunctional · demonstrated
Labels summarize the accepted research assessment. They do not indicate a test against your environment.
Reported exploitation
- Agonizing Serpens Rentdrv2 exploitation attemptreported exploitation
Technologies
Your stack
See the directory against your own environment.
Your stack
Check the software in your environment
Book a demo to see how Hinoki identifies affected software and validates exploitability in your environment.
Book a demo