DRIVE VULNEREBILITY HOME 2026 2025 2024 2023
|
DATE |
NAME |
INFO |
CATEGORY |
SUBCATE |
|
29.9.26 |
IoDrv.sys is a hardware I/O driver with an embedded TOPSTAR OVERSEAS ELECTRONICS Co.,Ltd signature. Beazley Security identified this exact sample, renamed Redacted.sys, in an INC ransomware affiliate intrusion. The accompanying Redacted EDR Blinder reportedly used the driver to modify security-driver code and impair endpoint defenses. The sample contains physical-memory mapping and port-I/O interfaces. The reported EDR-targeting logic belongs to the accompanying executable, not a built-in target list in the driver. Current Windows loading-policy compatibility and the runtime attack were not independently tested. | VULNEREBILITY | DRIVE | |
|
24.9.26 |
Antiy ATool AToolsKrnl64.sys from the reported 2.0.26.819 package exposes process termination through IOCTL 0x99000050. Its caller check validates an Antiy-signed executable on disk and caches the accepted process, but does not verify the integrity of the running client. A modified genuine client can therefore pass this check and request termination of caller-selected processes. Static analysis of this sample confirms a world-readable device and a kernel-mode target-open path that does not require the caller to already hold termination rights. The termination path rejects targets with a nonzero driver-defined protection/state byte. The public demonstration terminates only a self-created ordinary child; protected-process and EDR termination are not established. | VULNEREBILITY | DRIVE | |
|
24.9.26 |
BS_LED64.sys is the BIOSTAR I/O driver distributed with VIVID LED DJ. CVE-2026-94128 identifies vulnerable IOCTL handling in VIVID LED DJ 4.0.2411.1500. The included driver version 10.0.2410.1000 exposes physical-memory read and write operations through IOCTLs 0x226040 and 0x226044. These operations map a caller-supplied 32-bit physical starting address with MmMapIoSpace without an address allowlist. A public proof of concept embeds this exact driver sample. Exploitation requires the driver to be loaded and the caller to obtain access to its device; access from an unprivileged account has not been independently verified. | VULNEREBILITY | DRIVE | |
|
22.9.26 |
AMD Special Tools Driver AmdTools64.sys 1.7.16.219 exposes physical-memory mapping through IOCTL 0xFFF028A4. Static analysis confirms that the handler passes a caller-supplied physical address and length to MmMapIoSpace, constructs an MDL, and maps the range into the caller's user-mode address space with MmMapLockedPagesSpecifyCache, without a physical-range authorization check. | VULNEREBILITY | DRIVE | |
|
22.9.26 |
Malwarebytes' mbamchameleon.sys 3.2.0.456 exposes process termination to verified, registered client processes. The reported Bring Your Own Trusted Caller technique abuses administrator-level control of a genuine signed Malwarebytes client: the driver's on-disk image verification does not attest to the integrity of code executing inside that client. Static analysis confirms client verification and registration through IOCTL 0x222008 and a current-process client-state gate before IOCTL 0x222024 reaches ZwTerminateProcess for a supplied process identifier. An unrelated unsigned process does not meet those checks. The driver must be loaded and the caller must execute inside a verified, registered client. This record is limited to the reviewed sample and does not assert that all current product versions are affected. | VULNEREBILITY | DRIVE | |
| 18.9.26 | Panda Security's pskmad.sys 1.1.0.23 exposes a memory-read interface protected by a caller-supplied named-event and shared-section authentication exchange. An administrator-controlled process can satisfy that exchange and use the accepted handle to read memory through IOCTL 0xB3702C08. Static analysis of this exact sample confirms a path that copies from valid kernel virtual addresses into the IOCTL output. The device grants access to administrators and LocalSystem; this is not a standard-user entry point. This record tracks the newly reported authentication weakness, not the older Panda CVEs, and does not establish affected versions beyond this exact sample. | VULNEREBILITY | DRIVE | |
| 18.9.26 | MiniTool Partition Wizard's pwdrvio.sys exposes raw physical-disk read and write operations through the PartitionWizardDiskAccesser device namespace. The reviewed sample accepts a numeric device-name suffix, resolves the corresponding physical disk, and forwards caller-controlled read/write requests to the disk stack. Its device is created without FILE_DEVICE_SECURE_OPEN and its create handler does not authorize the caller opening that namespace path. Static analysis therefore supports the reported standard-user access to raw disk contents once the driver is loaded, which can bypass file-system access controls and enable privilege escalation. This is physical-disk access, not arbitrary physical-memory mapping; standard-user reachability was not reproduced locally. | VULNEREBILITY | DRIVE | |
| 18.9.26 | The legacy Prevx Scanner driver pxscan.sys 3.0.5.220 processes configurable file targets under its service's Files registry key when IOCTL 0x22E044 is requested. Static analysis confirms that the worker can delete selected files and terminate matching processes from kernel context. The process termination behavior is documented as CVE-2025-60349. The reviewed device uses FILE_DEVICE_SECURE_OPEN and a security descriptor granting full access only to LocalSystem and Builtin Administrators; modifying the service registry configuration also requires appropriate privileges. This is an administrator/SYSTEM-gated BYOVD primitive, not a standard-user privilege escalation. Protected-process termination was not tested locally. | VULNEREBILITY | DRIVE | |
| 16.9.26 | SakDriver is a malicious Windows kernel rootkit analyzed by 0xSec. It uses a registry callback for command dispatch and process-memory manipulation, conceals its driver file and service registry entries, and hides network connections through an NSI hook. It also implements WFP destination filtering and HTTP reporting. The sample uses the device name \Device\SakDriverWFP and carries a CrackerDrv.pdb path. These findings apply to the analyzed sample; current Windows loadability and HVCI compatibility have not been established. | VULNEREBILITY | DRIVE | |
| 11.9.26 | kgameprotect.sys exposes FILE_ANY_ACCESS IOCTL 0x222048 through \\.\kgameprotect. The handler accepts a caller-selected PID and opens that process from KernelMode with PROCESS_TERMINATE before calling ZwTerminateProcess. It performs no caller, registered-client, or target-PID authorization on this IOCTL branch. The reviewed sample is version 2.7.1.7 and also registers a file-system minifilter, so correct minifilter installation is required. Static review confirms the process-termination path, but does not establish that unprivileged users can open the device or that protected processes can be terminated on every Windows configuration. | VULNEREBILITY | DRIVE | |
| 9.9.26 | Fortinet FortiClient's fortimon3.sys minifilter exposes the Fortimon3FilterAntiExploitPort communication port to local administrators without additional caller ownership validation. The reviewed 2025.4.30.0 sample accepts a caller-selected process identifier and reaches ZwOpenProcess and ZwTerminateProcess from kernel context, allowing process termination that can impair endpoint defenses. CVE-2026-84386 affects FortiClient for Windows 7.2 and 7.4.0 through 7.4.7; Fortinet recommends upgrading to 7.4.8 or 8.0.0 and later. Product release numbers are distinct from the driver's PE file version. The minifilter must be loaded and its communication port accessible; this is not an unprivileged entry point. | VULNEREBILITY | DRIVE | |
| 9.9.26 | Nextron Systems identifies this exact sample as a rootkit combining network interception, obfuscated file operations, and security-product targeting. Observed and embedded filename metadata identify it as ampg.sys. Static analysis confirms WFP filtering and packet-injection paths, XOR-based file transformation, and a process-termination routine explicitly invoked for 360Tray.exe and ZhuDongFangYu.exe. Its embedded version fields claim Microsoft Corporation and SD Crashdump Port Driver; these are file metadata claims, not evidence of Microsoft authorship. No runtime test of successful security-product termination was performed. | VULNEREBILITY | DRIVE | |
| 8.9.26 | Nextron Systems identifies these samples as MemLoaderCustomize kernel PE-loader variants. Capabilities reported across the pair include kernel hooking, module hiding, and deletion; module hiding is specifically attributed to the c6825f94 sample. Static analysis confirms matching loader implementations that allocate image memory, copy PE sections, apply relocations, resolve kernel imports, and prepare mapped-image execution, together with file-deletion helpers. Both contain a MemLoaderCustomize.pdb build path. Module hiding and successful runtime self-deletion remain source-reported rather than dynamically tested. | VULNEREBILITY | DRIVE | |
| 8.9.26 | Nextron Systems identified PlugPlayService.sys as a heavily obfuscated, WHQL-signed malicious Windows kernel driver providing arbitrary memory access and direct access to RAID devices. Nextron catalogs this exact sample as an obfuscated kernel PE loader with arbitrary shellcode execution capabilities. Its embedded signature uses Microsoft Windows Hardware Compatibility Publisher. Nextron reports control-flow obfuscation similarities to RegPhantom and reports that xigmapper has deployed similar drivers; these observations do not establish that this exact sample is RegPhantom or was deployed by a particular xigmapper sample. Static analysis confirms encoded indirect calls, system-thread creation, physical-memory mapping, and enumeration of Disk driver device objects. The neonddu.sys sample has byte-identical PE sections and the same Authentihash as PlugPlayService.sys, but has a different embedded signature that fails cryptographic verification; the WHQL signing observation applies to PlugPlayService.sys, not neonddu.sys. | VULNEREBILITY | DRIVE | |
| 8.9.26 | Nextron Systems identifies this rksafe sample as a rootkit with input interception, anti-debugging, minifilter callbacks, and process protection. Static analysis confirms cross-process memory read/write routines, minifilter registration with a communication port, process and thread object callbacks, and logic that clears KdDebuggerEnabled. Input interception and successful runtime protection effects were not independently tested. | VULNEREBILITY | DRIVE |