← Back to driver explorer
Driver intelligenceVulnerableVerified
MsIo32.sys
The MsIo64.sys and MsIo32.sys drivers in Patriot Viper RGB before 1.1 allow local users (including low integrity processes) to read and write to arbitrary memory locations, and consequently gain NT AUTHORITY\SYSTEM privileges, by mapping \Device\PhysicalMemory into the calling process via ZwOpenSection and ZwMapViewOfSection.
Known samples 1
0 recorded TRUE · 1 recorded FALSE · 0 unknown for loading despite HVCI. Results apply to individual samples.
MsIo32.sysSample 1 · HVCI FALSE
- MD5
d9e7e5bcc5b01915dbcef7762a7fc329- SHA1
e6305dddd06490d7f87e3b06d09e9d4c1c643af0- SHA256
525d9b51a80ca0cd4c5889a96f857e73f3a80da1ffbae59851e0f51bdfb0b6cd- Imphash
8a424cd36ae3eab0d11332ce3b982a02- Authentihash MD5
6491c34f274a0ed6258fadca85bd69fb- Authentihash SHA1
7e732acb7cfad9ba043a9350cdeff25d742becb8- Authentihash SHA256
7018d515a6c781ea6097ca71d0f0603ad0d689f7ec99db27fcacd492a9e86027- Machine
- AMD64
- Version
- Not recorded
- Publisher
- Not recorded
Recorded command
sc.exe create MsIo32.sys binPath=C:\windows\temp\MsIo32.sys type=kernel && sc.exe start MsIo32.sysElevate privileges · Privileges: kernel · OS: Windows 10

