CVE-2025-51619: n/a
CVE-2025-51619 is a vulnerability in the Thesycon DPC Latency Checker driver (dpc.sys) through version 1.4.0. It allows local unprivileged users to cause a denial-of-service (system crash) on Windows systems by exploiting an IOCTL interface that improperly handles user-supplied pointers. This leads to arbitrary kernel memory access and a Blue Screen of Death (BSOD).
AI Analysis
Technical Summary
The Thesycon DPC Latency Checker driver (dpc.sys) up to version 1.4.0 contains a vulnerability where the IOCTL interface 0x81772008 accepts user-controlled input without proper pointer validation. The driver dereferences a user-supplied pointer and uses the resulting value in a call to the kernel API ExSetTimerResolution. This improper handling results in arbitrary kernel memory access, causing a denial-of-service condition (system crash) on affected Windows systems.
Potential Impact
Exploitation of this vulnerability allows a local unprivileged user to cause a denial-of-service by crashing the system (BSOD). There is no indication of confidentiality or integrity impact. The CVSS score is 5.5 (medium severity) reflecting the local attack vector and denial-of-service impact only.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict local access to trusted users only to prevent exploitation. No official fix or workaround has been documented at this time.
CVE-2025-51619: n/a
Description
CVE-2025-51619 is a vulnerability in the Thesycon DPC Latency Checker driver (dpc.sys) through version 1.4.0. It allows local unprivileged users to cause a denial-of-service (system crash) on Windows systems by exploiting an IOCTL interface that improperly handles user-supplied pointers. This leads to arbitrary kernel memory access and a Blue Screen of Death (BSOD).
CVSS v3.1
Score 5.5medium
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Thesycon DPC Latency Checker driver (dpc.sys) up to version 1.4.0 contains a vulnerability where the IOCTL interface 0x81772008 accepts user-controlled input without proper pointer validation. The driver dereferences a user-supplied pointer and uses the resulting value in a call to the kernel API ExSetTimerResolution. This improper handling results in arbitrary kernel memory access, causing a denial-of-service condition (system crash) on affected Windows systems.
Potential Impact
Exploitation of this vulnerability allows a local unprivileged user to cause a denial-of-service by crashing the system (BSOD). There is no indication of confidentiality or integrity impact. The CVSS score is 5.5 (medium severity) reflecting the local attack vector and denial-of-service impact only.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict local access to trusted users only to prevent exploitation. No official fix or workaround has been documented at this time.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- mitre
- Date Reserved
- 2025-06-16T00:00:00.000Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6aa1ae89acd9273b49bc6794
Added to database: 09/09/2026, 19:07:53 UTC
Last enriched: 09/09/2026, 19:22:41 UTC
Last updated: 09/09/2026, 23:14:51 UTC
Views: 7
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.