← Back to driver explorer
Driver intelligenceVulnerableVerified

MsIo32.sys

The MsIo64.sys and MsIo32.sys drivers in Patriot Viper RGB before 1.1 allow local users (including low integrity processes) to read and write to arbitrary memory locations, and consequently gain NT AUTHORITY\SYSTEM privileges, by mapping \Device\PhysicalMemory into the calling process via ZwOpenSection and ZwMapViewOfSection.

UUID / 4e5064b4-48d3-418c-a7a8-f0dc7ac0a176ADDED / 2023-01-09AUTHOR / Michael Haag

Known samples 1

0 recorded TRUE · 1 recorded FALSE · 0 unknown for loading despite HVCI. Results apply to individual samples.

MsIo32.sysSample 1 · HVCI FALSE
MD5
d9e7e5bcc5b01915dbcef7762a7fc329
SHA1
e6305dddd06490d7f87e3b06d09e9d4c1c643af0
SHA256
525d9b51a80ca0cd4c5889a96f857e73f3a80da1ffbae59851e0f51bdfb0b6cd
Imphash
8a424cd36ae3eab0d11332ce3b982a02
Authentihash MD5
6491c34f274a0ed6258fadca85bd69fb
Authentihash SHA1
7e732acb7cfad9ba043a9350cdeff25d742becb8
Authentihash SHA256
7018d515a6c781ea6097ca71d0f0603ad0d689f7ec99db27fcacd492a9e86027
Machine
AMD64
Version
Not recorded
Publisher
Not recorded

Recorded command

sc.exe create MsIo32.sys binPath=C:\windows\temp\MsIo32.sys type=kernel && sc.exe start MsIo32.sys

Elevate privileges · Privileges: kernel · OS: Windows 10

Research & references