← Back to driver explorer
Driver intelligenceVulnerableVerified

KfeCo10X64.sys

Killer exposes COM interfaces that allow non-privileged users 1) to block network for any process 2) to manage any service in the OS. Killer is preinstalled to laptops equipped with Intel Killer NICs (e.g. Dell). Since Intel patched the vulnerability quietly, it's not clear which version is safe. Also, it is unclear which OEMs are affected. Dell is definitely in the list, but it is likely that other vendors with Killer NICs on board, such as Acer and MSI, are affected too. Some users think that Killer suite is required for the NIC to work properly, so they install it even after a fresh Windows install. This version is confirmed vulnerable based on the script usage from zwclose.

UUID / 3e0bf6dc-791b-4170-8c40-427e7299d93dADDED / 2023-05-12AUTHOR / Paul Michaud

Known samples 1

0 recorded TRUE · 1 recorded FALSE · 0 unknown for loading despite HVCI. Results apply to individual samples.

KfeCo10X64.sysSample 1 · HVCI FALSE
MD5
697f698b59f32f66cd8166e43a5c49c7
SHA1
f5d58452620b55c2931cba75eb701f4cde90a9e4
SHA256
b583414fcee280128788f7b39451c511376fe821f455d4f3702795e96d560704
Imphash
2df11474daf362b1b2fa3d3a89b6acbe
Authentihash MD5
9085c42a59541dbd2e05fec9c247a189
Authentihash SHA1
c46323ef4fd5f553003a92fdad0d3059564e481f
Authentihash SHA256
8bce4a327c9e77631c03057b0e45cdbb2e751194d42995c0310e3ccdd3d33b7c
Machine
AMD64
Version
9.7.4.11
Publisher
Rivet Networks, LLC.

Recorded command

sc.exe create KfeCo10X64.sys binPath=C:\windows\temp\KfeCo10X64.sys type=kernel && sc.exe start KfeCo10X64.sys

Elevate privileges · Privileges: kernel · OS: Windows 10

Research & references

Acknowledgement: zwclose zwclose