← Back to driver explorer
Driver intelligenceVulnerableVerified

szkg64.sys

The StopZilla driver is a forgotten but still exploitable vulnerable driver that allows arbitrary kernel memory writes via unvalidated IOCTLs (0x80002063 and 0x8000206F). Attackers can leverage it to escalate privileges, disable LSASS PPL protection, and even modify PreviousMode in _KTHREAD to execute user-mode code as kernel-mode, effectively bypassing security checks. Despite its risks, it remains unblocked by Microsoft’s Driver Block List and many AV/EDR solutions. This driver highlights the persistent threat of forgotten vulnerable drivers still exploitable in modern Windows environments.

UUID / 375e8de3-aae4-488d-8273-66744978b45fADDED / 2025-01-10AUTHOR / decoder

Known samples 1

0 recorded TRUE · 0 recorded FALSE · 1 unknown for loading despite HVCI. Results apply to individual samples.

szkg64.sysSample 1 · HVCI unknown
MD5
8598e4a12eaa945b35365dd2750b9777
SHA1
d7698828cdc3c96cc17fe2d4ff6d93bb0cd355d8
SHA256
6bc0e1c104fac4a8caa4237c7ae181ca11a043a3ee26426aeb7a90dc40281fad
Imphash
f5a9e7716a1b8e1d5f64dfacca5283d0
Authentihash MD5
392ed92d6a91fa7cd318e2846ce07490
Authentihash SHA1
c516d0e96129086f6096e1e38ae90ed4da736ccb
Authentihash SHA256
95ca14e045618fb38834d17c5cc176162a29d846c1463b840c9129fb9af47c68
Machine
AMD64
Version
3.0.24
Publisher
iS3 Inc.
View on VirusTotal ↗

Recorded command

sc.exe create szkg64.sys binPath=C:\windows\temp\szkg64.sys type=kernel && sc.exe start szkg64.sys

Elevate privileges · Privileges: kernel · OS: Windows 11

Research & references