CVE-2025-66680

7.1

WiseCleaner · Wise Force Deleter

Wise Force Deleter contains a vulnerability in the WiseDelfile64.sys driver, allowing a local attacker with low privileges to delete arbitrary files on the host system.

Executive summary

A vulnerability in the Wise Force Deleter driver allows local attackers to perform arbitrary file deletion, potentially leading to system instability or security bypass.

Vulnerability

The flaw exists within the WiseDelfile64.sys kernel-mode driver, which fails to properly validate requests. An attacker with low-level local access can leverage this component to delete arbitrary files on the underlying operating system.

Business impact

The ability for a local attacker to delete arbitrary files poses a significant risk to system integrity and availability. An attacker could potentially delete critical system files, security configurations, or application data, leading to unauthorized service disruption or the removal of forensic evidence. With a CVSS score of 7.1, this vulnerability is considered High severity due to the potential for significant impact on the host system.

Remediation

Immediate Action: Users should check the WiseCleaner website for the latest version of Wise Force Deleter and update immediately. If a patch is not yet available for your specific installation, consider restricting access to the system or deactivating the software until a secure version is confirmed.

Proactive Monitoring: Monitor system logs for unusual file deletion activity or unexpected process execution involving the WiseDelfile64.sys driver.

Compensating Controls: Implement endpoint security policies that restrict non-administrative users from loading or interacting with unsigned or sensitive kernel-mode drivers.

Exploitation status

Public Exploit Available: Yes, several public proof-of-concept repositories exist on GitHub for this vulnerability.

Analyst recommendation

Given the availability of public proof-of-concept code and the high potential for system impact, this vulnerability requires prompt attention. Organizations should audit their environments for any instances of Wise Force Deleter and ensure they are patched to a version beyond 7.3.2. Until a validated patch is applied, treat the affected systems as high-risk assets and restrict local user access accordingly.

More WiseCleaner CVEs

Sources