← Back to driver explorer
Driver intelligenceVulnerableVerified

ATSZIO.sys

ASUS ATSZIO64.sys version 0.2.1.7 is affected by CVE-2024-33222, which permits local privilege escalation and arbitrary code execution through crafted IOCTL requests. The tracked x64 build exposes MSR read and write through IOCTLs 0x88070F88 and 0x88070F8C, maps selected ranges of \Device\PhysicalMemory, and returns physical addresses for contiguous allocations. These unrestricted hardware primitives can be used to modify kernel state.

UUID / 23f11e19-0776-4dd4-9c9c-7f6b60f8553fADDED / 2023-01-09AUTHOR / Michael Haag

Known samples 2

0 recorded TRUE · 1 recorded FALSE · 1 unknown for loading despite HVCI. Results apply to individual samples.

ATSZIO.sysSample 1 · HVCI FALSE
MD5
b12d1630fd50b2a21fd91e45d522ba3a
SHA1
490109fa6739f114651f4199196c5121d1c6bdf2
SHA256
01e024cb14b34b6d525c642a710bfa14497ea20fd287c39ba404b10a8b143ece
Imphash
b19743993dc7f1d48b2a86fe9b9c91e3
Authentihash MD5
69a92cb6ac87c99f10b24eefa13f0b10
Authentihash SHA1
b66bf2b1b07f8f2bab1418131ae66b0a55265f73
Authentihash SHA256
0ff8bcc7f938ec71ee33fbe089d38e40a8190603558d4765c47b1b09e1dd764a
Machine
AMD64
Version
0.2.1.7
Publisher
ASUSTek Computer Inc.
ATSZIO64.sysSample 2 · HVCI unknown
MD5
7a17e05b826b145a57ecd0d57b9a7238
SHA1
ac193543255977e1d06c505bd6521aab51e68ed2
SHA256
ecb4b15a847e888d36ca4e317a5d1d8963a305cc9705896a7a6d3769697d9f2d
Imphash
fa2125bfdaa1ea28db816c32ec3b8f8a
Authentihash MD5
34f537a649772cc643ddab927d019b95
Authentihash SHA1
0c0df9703b85b36094566b22b17082d9de65725e
Authentihash SHA256
a7c4268ab333669a1514dd1251a1a39420c2def0c8fe59926f1184aaa356e362
Machine
AMD64
Version
Not recorded
Publisher
Not recorded

Recorded command

sc.exe create ATSZIO.sys binPath=C:\windows\temp\ATSZIO.sys type=kernel && sc.exe start ATSZIO.sys

Elevate privileges · Privileges: User · OS: Windows 10

Research & references

Acknowledgement: fluffycats31 @fluffycats31