What happened
A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.
Affected versions
Unknown product: See original advisory Fixed: See vendor advisory.
Why it matters
This source correlation may provide earlier visibility while structured CVE metadata is still being updated.
Detection & mitigation
- Review the original advisory and validate affected versions.
- Apply vendor-provided updates or mitigations when available.
Public PoC references
RepositoryAuthorFirst seenReference
Exploit-DB 52512Throttlestop Kernel Driver - Kernel Out-of-Bounds Write Privilege EscalationXavi Beltran2026-04-22VerifiedPoC-in-GitHub · wqsv/ThrottleStopPoCCVE-2025-7771: Arbitrary physical memory and I/O port read/write via ThrottleStop driver★ 18wqsv2025-08-31CandidatePoC-in-GitHub · Demoo1337/ThrottleStopCVE-2025-7771 ThrottleStop.sys privilege escalation exploit - unrestricted IOCTL access to physical memory via MmMapIoSpace★ 11Demoo13372025-09-07CandidatePoC-in-GitHub · Gabriel-Lacorte/CVE-2025-7771Arbitrary Function Call Exploit using the ThrottleStop driver★ 12Gabriel-Lacorte2025-10-03CandidatePoC-in-GitHub · AmrHuss/throttlestop-exploit-rwArbitrary physical memory read/write exploitation using ThrottleStop.sys (CVE-2025-7771) with superfetch address translation - Windows kernel security research★ 15AmrHuss2025-11-13CandidatePoC-in-GitHub · v31l0x1/ThrottleStopPPLPoc for CVE-2025-7771 to modify PPL Protection★ 5v31l0x12025-12-31CandidatePoC-in-GitHub · xM0kht4r/CVE-2025-7771A simple PoC demonstrating the vulnerability in the ThrottleStop.sys driver, showcasing arbitrary physical memory read and write capabilities, as well as virtual-to-physical address translation using Superfetch.★ 10xM0kht4r2026-01-13CandidatePoC-in-GitHub · lzty/CVE-2025-7771This Poc demonstrate Arbitrary read/write primitives provided by CVE-2025-7771★ 2lzty2026-01-21CandidatePoC-in-GitHub · DeathShotXD/0xKern3lCrushAdvanced PoC & Research for CVE-2026-0828 (Safetica) and CVE-2025-7771 (ThrottleStop). Analysis of BYOVD (Bring Your Own Vulnerable Driver) TTPs for Ring 0 process termination and physical memory R/W. Researching EDR-Killer patterns, PPL bypasses, and kernel-mode primitives used by MedusaLocker and other threat actors.★ 54DeathShotXD2026-02-04CandidatePoC-in-GitHub · D4rkks/CVE-2025-7771-Vulnerability-ExplorationEscalating privilege in the system from unsigned driver using throttlestop vulnerability★ 13D4rkks2026-04-17CandidatePoC-in-GitHub · mein-0/cve-2025-7771★ 0mein-02026-05-23CandidatePoC-in-GitHub · enessakircolak/CVE-2025-7771ThrottleStop.sys Arbitrary Physical Memory R/W★ 20enessakircolak2026-08-10CandidateSource timeline
Discovered through Exploit-DBView source ↗
Record history
Record created from the first normalized source observation.
Metadata and source references refreshed.