← Back to driver explorer
Driver intelligenceVulnerableVerified

ViveRRAudio.sys

Northwave Cyber Security contributed this driver based on in-house research. The driver has a CVSSv3 score of 5.5, indicating a information disclosure / local dos impact. This vulnerability could potentially be exploited for privilege escalation or other malicious activities.

UUID / 4cb95b41-43b4-4806-b536-ae5fd8c76b0eADDED / 2024-09-11AUTHOR / Northwave Cyber Security

Known samples 1

1 recorded TRUE · 0 recorded FALSE · 0 unknown for loading despite HVCI. Results apply to individual samples.

ViveRRAudio.sysSample 1 · HVCI TRUE
MD5
e548fef8b4c41ee672482dcc1af31aef
SHA1
4e40f2245f62669949ead77fc56bdbaf1d77ce99
SHA256
9d5e8700a434838eb63a0573178b4291f07a9d96dabfb4ead40253a3cd9edefd
Imphash
78eb92e96f5e824801f3284b813750ab
Authentihash MD5
590a32adaae270a9fe5c51f37c595f0d
Authentihash SHA1
d3ca88c4df0bd4e2ef3f438f9735897da7f9c6dc
Authentihash SHA256
c4020e95f8a69522e400d3b14bf1be4fec2e7db0597626fbd8f8c3c1e85bffa0
Machine
AMD64
Version
0,1,11,7
Publisher
HTC VIVE

Recorded command

sc.exe create ViveRRAudio binPath=C:\windows\temp\ViveRRAudio.sys type=kernel && sc.exe start ViveRRAudio

Elevate privileges · Privileges: kernel · OS: Windows 10

Research & references

Acknowledgement: Northwave Cyber Security