← Back to driver explorer
Driver intelligenceVulnerableVerified

SMARTEIO64.SYS

The Carbon Black Threat Analysis Unit (TAU) discovered 34 unique vulnerable drivers (237 file hashes) accepting firmware access. Six allow kernel memory access. All give full control of the devices to non-admin users. By exploiting the vulnerable drivers, an attacker without the system privilege may erase/alter firmware, and/or elevate privileges. As of the time of writing in October 2023, the filenames of the vulnerable drivers have not been made public until now.

UUID / 2a7a59c1-35b8-42b6-a560-2fbf4247a584ADDED / 2023-11-02AUTHOR / Takahiro Haruyama

Known samples 1

0 recorded TRUE · 1 recorded FALSE · 0 unknown for loading despite HVCI. Results apply to individual samples.

SMARTEIO64.SYSSample 1 · HVCI FALSE
MD5
bdd8dc8880dfbc19d729ca51071de288
SHA1
87d2b638e5dfab1e37961d27ca734b83ece02804
SHA256
3c95ebf3f1a87f67d2861dbd1c85dc26c118610af0c9fbf4180428e653ac3e50
Imphash
b84820037d6a51ba108e0e81ce01db0b
Authentihash MD5
4af56e8ccef0c6878fcbbc678748f508
Authentihash SHA1
4c3d1b103c3acb7120f0674fd33aba581736234b
Authentihash SHA256
e928948ee36fa14c99a9147cd3b8d4c8c1917c52b50857d922ac72ed55d1f8e7
Machine
AMD64
Version
5.13.01.2008-1.00
Publisher
EVGA Technology Inc.

Recorded command

sc.exe create SMARTEIO64SYS binPath= C:\windows\temp\SMARTEIO64SYS.sys type=kernel && sc.exe start SMARTEIO64SYS

Elevate privileges · Privileges: kernel · OS: Windows 10

Research & references