EDR killers exploit 34 vulnerable drivers via BYOVD, gaining kernel access to disable defenses, increasing ransomware success rates.
Because attacker-supplied flow data is used in public flows, the bug leads to unauthenticated remote code execution.