← Back to driver explorer
Driver intelligenceVulnerableVerified

ecsiodriverx64.sys

The Carbon Black Threat Analysis Unit (TAU) discovered 34 unique vulnerable drivers (237 file hashes) accepting firmware access. Six allow kernel memory access. All give full control of the devices to non-admin users. By exploiting the vulnerable drivers, an attacker without the system privilege may erase/alter firmware, and/or elevate privileges. As of the time of writing in October 2023, the filenames of the vulnerable drivers have not been made public until now.

UUID / 0f749d4e-145e-4b8e-bea6-47003d228043ADDED / 2023-11-02AUTHOR / Takahiro Haruyama

Known samples 2

0 recorded TRUE · 2 recorded FALSE · 0 unknown for loading despite HVCI. Results apply to individual samples.

ecsiodriverx64.sysSample 1 · HVCI FALSE
MD5
3a1ba5cd653a9ddce30c58e7c8ae28ae
SHA1
04967bfd248d30183992c6c9fd2d9e07ae8d68ad
SHA256
270547552060c6f4f5b2ebd57a636d5e71d5f8a9d4305c2b0fe5db0aa2f389cc
Imphash
d6f977640d4810a784d152e4d3c63a6b
Authentihash MD5
ce904544497eb65515a416258b2bfd91
Authentihash SHA1
6cfa176d71505d8651f82b367f96cb5c497648a5
Authentihash SHA256
9452b5577681c74d568825c4e95c5c9a5e0f682782c8dd932a7d4d732e958802
Machine
AMD64
Version
1.1.0.0
Publisher
Elitegroup Computer Systems
ecsiodriverx64.sysSample 2 · HVCI FALSE
MD5
f34489c0f0d0a16b4db8a17281b57eba
SHA1
3a1f19b7a269723e244756dac1fc27c793276fe7
SHA256
7de1ce434f957df7bbdf6578dd0bf06ed1269f3cc182802d5c499f5570a85b3a
Imphash
a095f31019d7a32d0a0507879a1822b1
Authentihash MD5
d9272a5a4b5add2159866e4af9e893d5
Authentihash SHA1
87f47eb2066556a20a15f6c777c35daa2bc30f55
Authentihash SHA256
5cbe195ef5e86f705c8290602ae688e1835e7385ed68ae264c4795e425c1645f
Machine
AMD64
Version
Not recorded
Publisher
Not recorded

Recorded command

sc.exe create ecsiodriverx64sys binPath= C:\windows\temp\ecsiodriverx64sys.sys type=kernel && sc.exe start ecsiodriverx64sys

Elevate privileges · Privileges: kernel · OS: Windows 10

Research & references