{"Id":"a7c3e2d1-8f4b-4e6a-b5d9-3c1f0e7a9b82","Tags":["CorMem.sys"],"Verified":"TRUE","Author":"Michael Haag","Created":"2026-04-06","MitreID":"T1068","Category":"vulnerable driver","Commands":{"Command":"sc.exe create CorMem.sys binPath=C:\\windows\\temp\\CorMem.sys type=kernel && sc.exe start CorMem.sys","Description":"Teledyne Digital Imaging CorMem.sys (Sapera Memory Manager) exposes physical memory read/write, contiguous memory allocation, and I/O port access to user-mode processes via CorMem.dll wrapper functions. The driver provides 36 exported functions including CorMemGetPhysMemory, CorMemMapPhysMemory, CorMemAllocPhysMemory, CorMemReadIo, and CorMemWriteIo. Actively abused for BYOVD with 0/71 VT detection. Execution parents include Cobalt Strike/IcedID malware and game cheat kernel loaders.","OperatingSystem":"Windows 10","Privileges":"kernel","Usecase":"Elevate privileges"},"Resources":["https://github.com/KeServiceDescriptorTable/cormem.sys-vulnerable-driver","https://www.virustotal.com/gui/file/40c855d20d497823716a08a443dc85846233226985ee653770bc3b245cf2ed0f","https://x.com/skept1kal/status/2040200734570877354"],"Detection":[],"Acknowledgement":{"Person":"skept1kal","Handle":"@skept1kal"},"KnownVulnerableSamples":[{"Filename":"CorMem.sys","MD5":"78fb9882e498d964f42169ce511f07fc","SHA1":"bceae6dc87c9c6c33555a4a9008be14c66fd1e20","SHA256":"40c855d20d497823716a08a443dc85846233226985ee653770bc3b245cf2ed0f","Signature":["Teledyne Digital Imaging Inc.","DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1","DigiCert Trusted Root G4"],"Date":"","Publisher":"","Company":"Teledyne Digital Imaging Inc.","Description":"Sapera Memory Manager","Product":"Sapera LT","ProductVersion":"9.00","FileVersion":"9.00","MachineType":"AMD64","OriginalFilename":"CorMem.sys","InternalName":"CorMem.sys","Copyright":"Copyright (c) Teledyne Digital Imaging Inc.1997-2024","Authentihash":{"MD5":"559ede4607c9953fc5804a575c9a661b","SHA1":"505b7c56888009ab3b9531caeee6fa9a9b88916a","SHA256":"475df18e82d6e8ee09cbc9896f23f75b71aba43b7592d4962737cdc9230eb52d"},"RichPEHeaderHash":{"MD5":"","SHA1":"","SHA256":""},"Imports":["ntoskrnl.exe","HAL.dll"],"ImportedFunctions":["RtlQueryRegistryValues","MmGetSystemRoutineAddress","RtlWriteRegistryValue","RtlCopyUnicodeString","RtlAppendUnicodeStringToString","RtlGetVersion","ExAllocatePoolWithTag","ExFreePoolWithTag","ObReferenceObjectByHandle","ZwClose","ZwOpenSection","ZwMapViewOfSection","KeInitializeEvent","IoBuildDeviceIoControlRequest","IofCallDriver","IoGetDeviceObjectPointer","ObReferenceObjectByPointer","ObfDereferenceObject","_vsnprintf","PsGetProcessId","KeInitializeMutex","RtlInitUnicodeString","KeWaitForSingleObject","MmProbeAndLockPages","MmUnlockPages","MmMapLockedPagesSpecifyCache","MmUnmapLockedPages","MmAllocatePagesForMdl","MmFreePagesFromMdl","MmAllocateContiguousMemory","MmFreeContiguousMemory","IoAllocateMdl","IofCompleteRequest","IoCreateDevice","IoCreateSymbolicLink","IoDeleteDevice","IoDeleteSymbolicLink","IoFreeMdl","IoGetCurrentProcess","IoIs32bitProcess","ZwUnmapViewOfSection","MmGetPhysicalAddress","MmIsAddressValid","__C_specific_handler","KeReleaseMutex","HalTranslateBusAddress"],"ExportedFunctions":"","Sections":{".text":{"Entropy":6.54,"Virtual Size":"0x9059"},".rdata":{"Entropy":4.67,"Virtual Size":"0xa60"},".data":{"Entropy":0.52,"Virtual Size":"0x1b0"},".pdata":{"Entropy":4.36,"Virtual Size":"0x408"},"NONPAGE":{"Entropy":0.02,"Virtual Size":"0x21c0"},".gfids":{"Entropy":0.81,"Virtual Size":"0x4"},"INIT":{"Entropy":5.32,"Virtual Size":"0x632"},".rsrc":{"Entropy":3.48,"Virtual Size":"0x410"},".reloc":{"Entropy":2.95,"Virtual Size":"0x30"}},"Signatures":[{"CertificatesInfo":"","SignerInfo":"","Certificates":[{"Subject":"C=US, O=DigiCert, Inc., CN=DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1","ValidFrom":"2021-04-29 00:00:00","ValidTo":"2036-04-28 23:59:59","Signature":"","SignatureAlgorithmOID":"1.2.840.113549.1.1.12","IsCertificateAuthority":true,"SerialNumber":"08ad40b260d29c4c9f5ecda9bd93aed9","Version":3,"CertificateType":"CA","IsCodeSigning":false,"IsCA":true,"TBS":{"MD5":"5d8003a64dfa5a4d88365da1566038cb","SHA1":"79465b56bc7ad55a37bdf633943da8bfc84db228","SHA256":"84bdc82e2f2a7f7aaa782667dac556ffcb2b33240c1f9c0a00a3264526a98332","SHA384":"65b1d4076a89ae273f57e6eeedecb3eae129b4168f76fa7671914cdf461d542255c59d9b85b916ae0ca6fc0fcf7a8e64"}},{"Subject":"C=CA, ST=Quebec, L=Saint,Laurent, O=Teledyne Digital Imaging Inc., CN=Teledyne Digital Imaging Inc.","ValidFrom":"2023-02-02 00:00:00","ValidTo":"2026-03-06 23:59:59","Signature":"","SignatureAlgorithmOID":"1.2.840.113549.1.1.12","IsCertificateAuthority":false,"SerialNumber":"0297014378a2ab05fe62be6d3e7c603c","Version":3,"CertificateType":"Leaf (Code Signing)","IsCodeSigning":true,"IsCA":false,"TBS":{"MD5":"bf2a8e47bb6af5750895d048d721c56a","SHA1":"e01a1d7b642c57506cfa33d18de17f7effa4c223","SHA256":"8b8e750fe315e9d2a90b47edd334ef8ac9061e755098d4910e112b688b1be065","SHA384":"7b3e6d39e0b6fdcd90d176a7fc107a8b2da2ca2f4f4bf7bfc1498a7e1bbe027ba49cd9e2542d39b8f7a7f36ecb985bf7"}}],"Signer":[{"SerialNumber":"0297014378a2ab05fe62be6d3e7c603c","Issuer":"C=US, O=DigiCert, Inc., CN=DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1","Version":1}]}],"Imphash":"d4c9146f538e07774dc7a0e570b47edc","LoadsDespiteHVCI":"FALSE"}]}