Silverfox Group is actively exploiting CVE-2025-70795 in wild to terminate AV processes.
Such driver is not in Windows vulnerable driver blocklist.
The updated driver verify if the control code is from a SYSTEM Process, but still can be used.
Reference: https://t.co/njs2DwqGf0 ht