CVE-2025-51619
Deferred Deferred - Pending Action

Denial-of-Service in Thesycon DPC Latency Checker Driver

Vulnerability report for CVE-2025-51619, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-09

Last updated on: 2026-09-09

Assigner: MITRE

Description

A vulnerability in the Thesycon DPC Latency Checker driver (dpc.sys) thru 1.4.0 allows local unprivileged users to cause a denial-of-service (BSOD) condition on Windows systems. The driver exposes an IOCTL interface (0x81772008) that accepts user-controlled input without validating pointers before passing them to kernel APIs. Specifically, it dereferences a user-supplied pointer and uses the resulting value in a call to ExSetTimerResolution, leading to an arbitrary kernel memory access. Exploiting this flaw results in a system crash.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-09
Last Modified
2026-09-09
Generated
2026-09-30
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-29
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
thesycon dpc_latency_checker 1.4.0
thesycon dpclatencychecker 1.4.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-20 The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is in the Thesycon DPC Latency Checker driver (dpc.sys) version 1.4.0 or earlier. It allows a local unprivileged user to crash the system with a Blue Screen of Death (BSOD). The driver has an IOCTL interface that accepts user input without validating pointers. When exploited, it dereferences a user-supplied pointer and passes it to a kernel API (ExSetTimerResolution), causing arbitrary kernel memory access and system instability.

Detection Guidance

Detecting this vulnerability requires checking for the presence of the vulnerable dpc.sys driver (version <=1.4.0) and monitoring for suspicious IOCTL requests. Use Process Explorer or WinObj to check for the driver device object. Look for unexpected calls to ExSetTimerResolution in kernel traces. No direct commands are provided in the resources, but monitoring for BSOD events related to dpc.sys may indicate exploitation attempts.

Impact Analysis

If you have the vulnerable driver installed, an attacker with local access to your system could exploit this flaw to crash your computer, leading to data loss or disruption of services. The attack requires local access but no special privileges, making it dangerous for systems running the affected software.

Compliance Impact

This vulnerability could impact compliance by causing system crashes, leading to potential data loss or unavailability of critical services. GDPR requires ensuring data integrity and availability, while HIPAA mandates protecting health information. A BSOD could violate these requirements if it results in unauthorized access or loss of protected data.

Mitigation Strategies

Immediate mitigation involves uninstalling the Thesycon DPC Latency Checker utility and removing the dpc.sys driver from the system. Since no patches are available, avoid using this software entirely. Block or restrict access to the vulnerable IOCTL interface (0x81772008) if removal is not possible. Monitor system logs for BSOD events linked to dpc.sys.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-51619. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart