← Back to driver explorer
Driver intelligenceVulnerableVerified
SMARTEIO64.SYS
The Carbon Black Threat Analysis Unit (TAU) discovered 34 unique vulnerable drivers (237 file hashes) accepting firmware access. Six allow kernel memory access. All give full control of the devices to non-admin users. By exploiting the vulnerable drivers, an attacker without the system privilege may erase/alter firmware, and/or elevate privileges. As of the time of writing in October 2023, the filenames of the vulnerable drivers have not been made public until now.
Known samples 1
0 recorded TRUE · 1 recorded FALSE · 0 unknown for loading despite HVCI. Results apply to individual samples.
SMARTEIO64.SYSSample 1 · HVCI FALSE
- MD5
bdd8dc8880dfbc19d729ca51071de288- SHA1
87d2b638e5dfab1e37961d27ca734b83ece02804- SHA256
3c95ebf3f1a87f67d2861dbd1c85dc26c118610af0c9fbf4180428e653ac3e50- Imphash
b84820037d6a51ba108e0e81ce01db0b- Authentihash MD5
4af56e8ccef0c6878fcbbc678748f508- Authentihash SHA1
4c3d1b103c3acb7120f0674fd33aba581736234b- Authentihash SHA256
e928948ee36fa14c99a9147cd3b8d4c8c1917c52b50857d922ac72ed55d1f8e7- Machine
- AMD64
- Version
- 5.13.01.2008-1.00
- Publisher
- EVGA Technology Inc.
Recorded command
sc.exe create SMARTEIO64SYS binPath= C:\windows\temp\SMARTEIO64SYS.sys type=kernel && sc.exe start SMARTEIO64SYSElevate privileges · Privileges: kernel · OS: Windows 10

