← Back to driver explorer
Driver intelligenceVulnerableVerified
ATSZIO.sys
ASUS ATSZIO64.sys version 0.2.1.7 is affected by CVE-2024-33222, which permits local privilege escalation and arbitrary code execution through crafted IOCTL requests. The tracked x64 build exposes MSR read and write through IOCTLs 0x88070F88 and 0x88070F8C, maps selected ranges of \Device\PhysicalMemory, and returns physical addresses for contiguous allocations. These unrestricted hardware primitives can be used to modify kernel state.
Known samples 2
0 recorded TRUE · 1 recorded FALSE · 1 unknown for loading despite HVCI. Results apply to individual samples.
ATSZIO.sysSample 1 · HVCI FALSE
- MD5
b12d1630fd50b2a21fd91e45d522ba3a- SHA1
490109fa6739f114651f4199196c5121d1c6bdf2- SHA256
01e024cb14b34b6d525c642a710bfa14497ea20fd287c39ba404b10a8b143ece- Imphash
b19743993dc7f1d48b2a86fe9b9c91e3- Authentihash MD5
69a92cb6ac87c99f10b24eefa13f0b10- Authentihash SHA1
b66bf2b1b07f8f2bab1418131ae66b0a55265f73- Authentihash SHA256
0ff8bcc7f938ec71ee33fbe089d38e40a8190603558d4765c47b1b09e1dd764a- Machine
- AMD64
- Version
- 0.2.1.7
- Publisher
- ASUSTek Computer Inc.
ATSZIO64.sysSample 2 · HVCI unknown
- MD5
7a17e05b826b145a57ecd0d57b9a7238- SHA1
ac193543255977e1d06c505bd6521aab51e68ed2- SHA256
ecb4b15a847e888d36ca4e317a5d1d8963a305cc9705896a7a6d3769697d9f2d- Imphash
fa2125bfdaa1ea28db816c32ec3b8f8a- Authentihash MD5
34f537a649772cc643ddab927d019b95- Authentihash SHA1
0c0df9703b85b36094566b22b17082d9de65725e- Authentihash SHA256
a7c4268ab333669a1514dd1251a1a39420c2def0c8fe59926f1184aaa356e362- Machine
- AMD64
- Version
- Not recorded
- Publisher
- Not recorded
Recorded command
sc.exe create ATSZIO.sys binPath=C:\windows\temp\ATSZIO.sys type=kernel && sc.exe start ATSZIO.sysElevate privileges · Privileges: User · OS: Windows 10
Research & references
Acknowledgement: fluffycats31 @fluffycats31

