← Back to driver explorer
Driver intelligenceVulnerableVerified
iqvw64e.sys
(1) IQVW32.sys before 1.3.1.0 and (2) IQVW64.sys before 1.3.1.0 in the Intel Ethernet diagnostics driver for Windows allows local users to cause a denial of service or possibly execute arbitrary code with kernel privileges via a crafted (a) 0x80862013, (b) 0x8086200B, (c) 0x8086200F, or (d) 0x80862007 IOCTL call.
Known samples 1
0 recorded TRUE · 1 recorded FALSE · 0 unknown for loading despite HVCI. Results apply to individual samples.
iqvw64e.sysSample 1 · HVCI FALSE
- MD5
1898ceda3247213c084f43637ef163b3- SHA1
d04e5db5b6c848a29732bfd52029001f23c3da75- SHA256
4429f32db1cc70567919d7d47b844a91cf1329a6cd116f582305f3b7b60cd60b- Imphash
55db306bc2be3ff71a6b91fd9db051b8- Authentihash MD5
1789a16d20ca2b55f491ad71848166a2- Authentihash SHA1
2cbfe4ad0e1231ff3e19c19ca9311d952ce170b7- Authentihash SHA256
785e87bc23a1353fe0726554fd009aca69c320a98445a604a64e23ab45108087- Machine
- AMD64
- Version
- 1.03.0.7 built by: WinDDK
- Publisher
- Intel Corporation
Recorded command
sc.exe create iqvw64e.sys binPath=C:\windows\temp\iqvw64e.sys type=kernel && sc.exe start iqvw64e.sysElevate privileges · Privileges: kernel · OS: Windows 10
Research & references
- https://www.crowdstrike.com/blog/scattered-spider-attempts-to-avoid-detection-with-bring-your-own-vulnerable-driver-tactic/
- https://expel.com/blog/well-that-escalated-quickly-how-a-red-team-went-from-domain-user-to-kernel-memory/
- https://github.com/Exploitables/CVE-2015-2291
- https://github.com/Tare05/Intel-CVE-2015-2291
- https://github.com/TheCruZ/kdmapper
- https://gist.github.com/k4nfr3/af970e7facb09195e56f2112e1c9549c

