← Back to driver explorer
Driver intelligenceVulnerableVerified

pstrip64.sys

pstrip64.sys is the EnTech Taiwan PowerStrip x64 kernel-mode driver, signed by EnTech Taiwan. In PowerStrip version 3.90.736 and earlier, the driver's IOCTL dispatcher exposes code 0x80002008, which maps caller-supplied physical memory directly into the requesting user-mode process and returns the mapped virtual base address, giving a local user an arbitrary physical read/write primitive. Public exploitation of CVE-2026-29923 uses this to scan physical memory for the EPROCESS 'Proc' pool tag, copy the SYSTEM process token, and overwrite the caller's token to escalate to NT AUTHORITY\SYSTEM.

UUID / 1db2dd90-5b8e-43c3-a39b-61e0614fb2abADDED / 2026-06-25AUTHOR / Aryu-RU

Known samples 1

0 recorded TRUE · 0 recorded FALSE · 1 unknown for loading despite HVCI. Results apply to individual samples.

pstrip64.sysSample 1 · HVCI unknown
MD5
23eed24b0a780863df35b500c4ea0733
SHA1
af413e76094f8a60d06d161a270427c6c2e3c018
SHA256
ab01485bb7c8bc1a9c86096eeea6d31d8fad557bf4d44072b46373d2203faa6e
Imphash
9c9e46c46aee658661dab538a361b117
Authentihash MD5
7b3dd9835689db0ccd3741e6023d0f11
Authentihash SHA1
3cba01d9fd8670a12ce987f17c16a1c05fed80b7
Authentihash SHA256
fd826f76a840c23d643611ab94d39b86aed4da221cdd7bfc688aaaf7cc8b64d7
Machine
AMD64
Version
1.0
Publisher
EnTech Taiwan

Recorded command

sc.exe create pstrip64 binPath=C:\windows\temp\pstrip64.sys type=kernel && sc.exe start pstrip64

Arbitrary physical memory read/write from user mode, abused for local privilege escalation to SYSTEM via token theft. · Privileges: User · OS: Windows 10, Windows 11

Research & references

Acknowledgement: athenasec16 @athenasec16