pstrip64.sys
pstrip64.sys is the EnTech Taiwan PowerStrip x64 kernel-mode driver, signed by EnTech Taiwan. In PowerStrip version 3.90.736 and earlier, the driver's IOCTL dispatcher exposes code 0x80002008, which maps caller-supplied physical memory directly into the requesting user-mode process and returns the mapped virtual base address, giving a local user an arbitrary physical read/write primitive. Public exploitation of CVE-2026-29923 uses this to scan physical memory for the EPROCESS 'Proc' pool tag, copy the SYSTEM process token, and overwrite the caller's token to escalate to NT AUTHORITY\SYSTEM.
Known samples 1
0 recorded TRUE · 0 recorded FALSE · 1 unknown for loading despite HVCI. Results apply to individual samples.
pstrip64.sysSample 1 · HVCI unknown
- MD5
23eed24b0a780863df35b500c4ea0733- SHA1
af413e76094f8a60d06d161a270427c6c2e3c018- SHA256
ab01485bb7c8bc1a9c86096eeea6d31d8fad557bf4d44072b46373d2203faa6e- Imphash
9c9e46c46aee658661dab538a361b117- Authentihash MD5
7b3dd9835689db0ccd3741e6023d0f11- Authentihash SHA1
3cba01d9fd8670a12ce987f17c16a1c05fed80b7- Authentihash SHA256
fd826f76a840c23d643611ab94d39b86aed4da221cdd7bfc688aaaf7cc8b64d7- Machine
- AMD64
- Version
- 1.0
- Publisher
- EnTech Taiwan
Recorded command
sc.exe create pstrip64 binPath=C:\windows\temp\pstrip64.sys type=kernel && sc.exe start pstrip64Arbitrary physical memory read/write from user mode, abused for local privilege escalation to SYSTEM via token theft. · Privileges: User · OS: Windows 10, Windows 11
Research & references
Acknowledgement: athenasec16 @athenasec16

