{"Id":"11d2230e-d9a4-5841-a508-ca8ffa827e56","Tags":["sysdiag.sys"],"Verified":"TRUE","Author":"Xusheng Li","Created":"2026-09-19","MitreID":"T1562.001","Category":"vulnerable driver","Commands":{"Command":"","Description":"Huorong sysdiag.sys 6.0.0.3 contains an IOCTL 0x2200b8 path that resolves a supplied process identifier and calls ZwTerminateProcess. The reported Bring Your Own Trusted Caller (BYOTC) chain uses administrator-level control of a genuine Huorong client to reach the product-restricted interface; trusting the client image does not establish the integrity of code executing inside it. Static analysis of this exact sample confirms the dispatcher and termination helper, while the client-classification bypass and ordinary-child termination result are externally reported. The driver must be loaded and the product-specific caller conditions met. This record does not establish access from a standard user, termination of protected processes, or applicability to other versions.","Usecase":"Abuse a trusted client to reach a kernel process-termination interface.","Privileges":"Administrator-level control of a genuine Huorong client in the reported product configuration.","OperatingSystem":"Windows"},"Resources":["https://github.com/magicsword-io/LOLDrivers/issues/440","https://gist.github.com/xusheng6/8b53a102d81b22d53e0c47c03a3a5cda","https://xusheng.dev/posts/byotc/main/"],"Acknowledgement":{"Person":"Xusheng Li","Handle":"@xusheng6"},"Detection":[],"KnownVulnerableSamples":[{"Filename":"sysdiag.sys","SHA256":"5aeae04dd27ff148cb8c0f646e34b0404a963b8ec6fc930e75ae5b09d5ec3291","MD5":"1b2497558f05c560e25b09c45d033245","SHA1":"6e3bf05225d003e401e81edbe38afc7aa7156cb5","Imphash":"54f82d5e9dac107659ee1b9ed28e8856","Authentihash":{"MD5":"74714572f39906324544a315a7e9f6fb","SHA1":"422539d16cdcadfbb9e76d1b70279bb6d69280ad","SHA256":"33d8462183bc0c8bb5a2a8530ce1842fd60f1610d00f9616444ec3946f121663"},"RichPEHeaderHash":{"MD5":"08e621d01ba67960f499b156b48af7d7","SHA1":"07bc2a4899bca31878de752a1420c677ad2497f7","SHA256":"c2ccea5c856e3cac1a522e52b7038ab8d2f9a816c933ef01cb022bbc6e9122cb"},"Sections":{".text":{"Entropy":6.5169293261346555,"Virtual Size":"0x6416a"},".rdata":{"Entropy":5.836835886570976,"Virtual Size":"0xc994"},".data":{"Entropy":4.351352399984065,"Virtual Size":"0xe7458"},".pdata":{"Entropy":5.879106214536045,"Virtual Size":"0x58b0"},".asmstub":{"Entropy":3.7285387341647955,"Virtual Size":"0x31"},"PAGE":{"Entropy":6.27931942892573,"Virtual Size":"0x1987"},"INIT":{"Entropy":5.143450730399943,"Virtual Size":"0x1ee6"},".rsrc":{"Entropy":3.2551980193378935,"Virtual Size":"0x3c0"},".reloc":{"Entropy":5.189760972651427,"Virtual Size":"0x2a8"}},"MagicHeader":"50 45 0 0","CreationTimestamp":"2026-07-29 20:59:09","Description":"System Diagnosis Toolkit","Company":"Beijing Huorong Network Technology Co., Ltd.","InternalName":"sysdiag","OriginalFilename":"sysdiag.sys","FileVersion":"6.0.0.3","Product":"Huorong Internet Security","ProductVersion":"6.0.0.0","Copyright":"Beijing Huorong Network Technology Co., Ltd.","MachineType":"AMD64","Imports":["ntoskrnl.exe","HAL.dll","FLTMGR.SYS","NDIS.SYS"],"ExportedFunctions":"","ImportedFunctions":["IoCsqInsertIrp","IoCsqRemoveNextIrp","ObReferenceObjectByHandle","ObfDereferenceObject","ZwClose","KeStackAttachProcess","KeUnstackDetachProcess","IoGetRequestorProcess","__C_specific_handler","PsThreadType","RtlGetVersion","IoRegisterBootDriverReinitialization","IoRegisterDriverReinitialization","NtBuildNumber","ExAllocatePoolWithTag","ExFreePoolWithTag","ExInitializePagedLookasideList","ExDeletePagedLookasideList","RtlCompareUnicodeString","RtlPrefixUnicodeString","KeResetEvent","MmBuildMdlForNonPagedPool","MmUnmapLockedPages","ExEventObjectType","wcschr","wcsncmp","KeQueryTimeIncrement","ProbeForWrite","ExGetPreviousMode","IofCompleteRequest","IoCreateDevice","IoCreateSymbolicLink","IoDeleteDevice","IoDeleteSymbolicLink","ZwOpenSymbolicLinkObject","ZwQuerySymbolicLinkObject","ExRaiseAccessViolation","MmIsAddressValid","PsGetProcessId","PsGetThreadProcessId","ZwOpenProcess","PsLookupProcessByProcessId","ObOpenObjectByPointer","ObQueryNameString","PsGetProcessPeb","ZwQueryInformationProcess","IoFileObjectType","PsProcessType","MmUserProbeAddress","PsSetCreateProcessNotifyRoutine","PsSetCreateThreadNotifyRoutine","PsSetLoadImageNotifyRoutine","ZwOpenKey","ZwSetValueKey","PsGetCurrentProcessId","wcsncpy","_wcsnicmp","RtlFreeUnicodeString","ZwOpenFile","ZwQueryInformationFile","RtlUpcaseUnicodeString","RtlRandomEx","FsRtlIsNameInExpression","PsGetCurrentThreadId","_snprintf","qsort","strchr","wcsrchr","wcsstr","_wcslwr","RtlCopyUnicodeString","KeDelayExecutionThread","ExQueueWorkItem","MmProtectMdlSystemAddress","IoGetTopLevelIrp","IoAllocateWorkItem","IoFreeWorkItem","IoQueueWorkItem","ObfReferenceObject","ZwCreateFile","ZwCreateSection","ZwOpenSection","ZwQueryValueKey","ZwTerminateProcess","PsIsThreadTerminating","IoCsqInitialize","ZwQuerySecurityObject","swprintf","KeInitializeApc","KeInsertQueueApc","ZwQuerySystemInformation","strncmp","_strnicmp","strrchr","_vsnprintf","ZwAllocateVirtualMemory","ZwFreeVirtualMemory","strncpy","KeAcquireInStackQueuedSpinLock","KeReleaseInStackQueuedSpinLock","RtlWalkFrameChain","IoGetDeviceObjectPointer","_vsnwprintf","RtlInitializeBitMap","RtlSetBit","RtlClearAllBits","RtlFindClearBitsAndSet","RtlClearBits","RtlInitializeGenericTableAvl","RtlInsertElementGenericTableAvl","RtlDeleteElementGenericTableAvl","RtlLookupElementGenericTableAvl","RtlEnumerateGenericTableAvl","RtlDecompressBuffer","ZwSetInformationThread","RtlAppendUnicodeToString","KeAreApcsDisabled","IoBuildAsynchronousFsdRequest","IofCallDriver","IoFreeIrp","IoSetCompletionRoutineEx","IoSetThreadHardErrorMode","RtlUpcaseUnicodeChar","RtlUnicodeStringToAnsiString","RtlFreeAnsiString","RtlCompareMemory","ZwReadFile","ZwWaitForSingleObject","IoBuildDeviceIoControlRequest","IoCreateFile","IoQueryFileInformation","FsRtlInsertPerStreamContext","FsRtlLookupPerStreamContextInternal","RtlQueryRegistryValues","CmRegisterCallback","ZwDeleteKey","IoAttachDeviceToDeviceStackSafe","ObReferenceObjectByName","IoDriverObjectType","KeClearEvent","IoAllocateIrp","IoQueueThreadIrp","MmAllocatePagesForMdl","MmFreePagesFromMdl","MmSystemRangeStart","IoGetFileObjectGenericMapping","ObInsertObject","SeCreateAccessState","ObCreateObject","PsLookupThreadByThreadId","ZwQueryObject","ZwCreateEvent","ZwFsControlFile","PsGetThreadTeb","ZwQueryInformationThread","IoDeviceObjectType","IoGetCurrentProcess","IoFreeMdl","IoAllocateMdl","PsTerminateSystemThread","PsCreateSystemThread","MmMapLockedPagesSpecifyCache","MmGetSystemRoutineAddress","MmUnlockPages","MmProbeAndLockPages","ExWaitForRundownProtectionRelease","ExReleaseRundownProtection","ExAcquireRundownProtection","ExInitializeRundownProtection","ExDeleteResourceLite","ExReleaseResourceLite","ExAcquireResourceExclusiveLite","ExAcquireResourceSharedLite","ExInitializeResourceLite","ExDeleteNPagedLookasideList","ExInitializeNPagedLookasideList","ExpInterlockedPushEntrySList","ExpInterlockedPopEntrySList","ExQueryDepthSList","ExReleaseFastMutex","ExAcquireFastMutex","KeReleaseSpinLock","KeAcquireSpinLockRaiseToDpc","KeWaitForSingleObject","KeWaitForMultipleObjects","KeLeaveCriticalRegion","KeEnterCriticalRegion","KeSetPriorityThread","KeSetEvent","KeInitializeEvent","ZwSetSecurityObject","_snwprintf","RtlLengthSecurityDescriptor","SeCaptureSecurityDescriptor","RtlCreateSecurityDescriptor","RtlSetDaclSecurityDescriptor","RtlAbsoluteToSelfRelativeSD","IoIsWdmVersionAvailable","SeExports","RtlLengthSid","RtlAddAccessAllowedAce","RtlGetSaclSecurityDescriptor","RtlGetDaclSecurityDescriptor","RtlGetGroupSecurityDescriptor","RtlGetOwnerSecurityDescriptor","ZwCreateKey","RtlInitUnicodeString","towlower","ZwQueryDirectoryFile","KeBugCheckEx","MmGetPhysicalAddress","ExFreePool","MmMapIoSpace","MmUnmapIoSpace","PsRemoveLoadImageNotifyRoutine","KeQueryPerformanceCounter","FltQueryVolumeInformation","FltEnumerateFilters","FltGetFileNameInformationUnsafe","FltGetRequestorProcessId","FltQueueDeferredIoWorkItem","FltFreeDeferredIoWorkItem","FltAllocateDeferredIoWorkItem","FltGetDiskDeviceObject","FltCancelFileOpen","FltGetDestinationFileNameInformation","FltGetFileNameInformation","FltCompletePendedPostOperation","FltCompletePendedPreOperation","FltStartFiltering","FltUnregisterFilter","FltRegisterFilter","FltSetCallbackDataDirty","FltObjectDereference","FltCreateSystemVolumeInformationFolder","FltOpenVolume","FltGetVolumeName","FltQueryInformationFile","FltParseFileName","FltClose","FltFsControlFile","FltFlushBuffers","FltSetInformationFile","FltWriteFile","FltReadFile","FltCreateFileEx","FltReleaseFileNameInformation","NdisReleaseReadWriteLock","NdisAcquireReadWriteLock","NdisInitializeReadWriteLock"],"Signatures":[{"CertificatesInfo":"","SignerInfo":"","Certificates":[{"Subject":"C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Windows Hardware Compatibility Publisher","ValidFrom":"2025-11-13 19:59:40","ValidTo":"2026-11-10 19:59:40","Signature":"86e91c9dd77bcbe24e9c811c4ec9c47116d9d554243f04666bef14828edbfeb665280fa10b643a59d05c4db8b5f2bae0657af9a75457236e455f956ed7ba65f7e8019355d00e322f681ab15f14718b34bff1e50d8cde1217dc158c31a875b17fa45f015b4b2a30c471d43345257c729d83c2287716b3d19c177ed341da95687f8af92cfebc42e1e4439eb4304762e17feb85a09316afe8153e4783a98153d91249d29da0bca831ea6ccd93bace88fc284e82987df65bcd8ab0263a2da5e178e710c26e8abec12fe398782d1f1bc669ec9c5cbf3010f8e2600133a59fb8269daba61e5b2facee4f96ba19f9cfaef3fdb21e933a65c3245f6de70cb08f28f2c818","SignatureAlgorithmOID":"1.2.840.113549.1.1.11","IsCertificateAuthority":false,"SerialNumber":"330000013c4a61fb3578d2b6dd00000000013c","Version":3,"CertificateType":"Leaf (Code Signing)","IsCodeSigning":true,"IsCA":false,"TBS":{"MD5":"93354b540685ae615b51e692ea0895de","SHA1":"b38cd5d491c85bd55e9b111e98430171a01e9515","SHA256":"037c041a283132dc57d29bc339b4d0d006787e32ac0a60afd7206c41c9fbf61f","SHA384":"bbef5ad51ba2a76ba3f0e39459837c9533a56420db0da55814511346155922c98ae905d6541df5a79895ce1a51d53491"}},{"Subject":"C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Windows Third Party Component CA 2012","ValidFrom":"2012-04-18 23:48:38","ValidTo":"2027-04-18 23:58:38","Signature":"5a8a67daccd5fd0d264177bf0a4678b4b3de12692b7723c2652f015fd203f461ba509d2e8c3972f36c3e6ab11e766decb7f382dcccbbc56970287366173f54ebee011648c446d91b80ae813a8d0f796d68b09eea2d3f39d3ca387ebd5e7c086e19dcc6c2f438336861e2524783e1000156d2bacb878205310a418b4ee77f5f5fed5fd3392d45eba213bffd1ec298417161165fc80a70257c59693124e471e70abb0417f79f721ec9d2bb1abe3d02fe090cb243b4591a99539396215fe0d6b72601429536ac27fdbef48577683d18bdf4be98882211865216f345ec0397107087a37043713cdbc98603170cf5735bc67de15c64edd7c548d7ed32e2d1aad3cfa7f6574e61f977eb67f288b3de00da038fd08a34373e1dd862b8d2b1f3e12f8b723b81967c6ffcec667672601b24f2a0896d5b6d002eef28dd868705c2b4b9e5be64c22af24a155c98e2c42785ff52e3627e0fb2020bd766c70ab2d33d200414503259830a7d9bed5a38120152ba2f5e20728e4af1fde771028c3be107bec973f4dd47d8b4efb4a4b330b9893e76cab90098567eabea8ab8a5d038ab6977130b142fe9aa411ff7babd3a2b348aee0aab63e663f788248e200d2b3b9de3c24952ac9f1f0e393b5dd46e506ae67d523aaa7c3315290d265e0158a74ea93d7a846f743f609fe4324f3600af6d71d33ea646655f8174f1fec171da4ca0415a82ddf11f","SignatureAlgorithmOID":"1.2.840.113549.1.1.11","IsCertificateAuthority":true,"SerialNumber":"610baac1000000000009","Version":3,"CertificateType":"CA","IsCodeSigning":false,"IsCA":true,"TBS":{"MD5":"a569061297e8e824767dbc3184a69bea","SHA1":"adbb26a587a8f44b4fccaecb306f980d1c55a150","SHA256":"cec1afd0e310c55c1dcc601ab8e172917706aa32fb5eaf826813547fdf02dd46","SHA384":"e947cac936803f5683196e4ff1b259096073395d0b908522ddce90d57597c9f7b57f7ddcdbe021ba863d843c340da8ba"}}],"Signer":[{"SerialNumber":"330000013c4a61fb3578d2b6dd00000000013c","Issuer":"C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Windows Third Party Component CA 2012","Version":1}]}],"Signature":["Microsoft Windows Hardware Compatibility Publisher"]}]}