← Back to driver explorer
Driver intelligenceVulnerableVerified

avalueio.sys

The Carbon Black Threat Analysis Unit (TAU) discovered 34 unique vulnerable drivers (237 file hashes) accepting firmware access. Six allow kernel memory access. All give full control of the devices to non-admin users. By exploiting the vulnerable drivers, an attacker without the system privilege may erase/alter firmware, and/or elevate privileges. As of the time of writing in October 2023, the filenames of the vulnerable drivers have not been made public until now.

UUID / 4f0a65a7-9a01-40cb-8d95-0844515103e6ADDED / 2023-11-02AUTHOR / Takahiro Haruyama

Known samples 2

0 recorded TRUE · 2 recorded FALSE · 0 unknown for loading despite HVCI. Results apply to individual samples.

avalueio.sysSample 1 · HVCI FALSE
MD5
1da1cfe6aa15325c9ecf8f8c9b2cd12d
SHA1
b406920634361f4b7d7c1ec3b11bb40872d85105
SHA256
a5a4a3c3d3d5a79f3ed703fc56d45011c21f9913001fcbcc43a3f7572cff44ec
Imphash
340e874a1ca966e45fc2a314ef228cce
Authentihash MD5
f076a50a4c93a86cdacb0de3f4a368f6
Authentihash SHA1
fc63767819c74d78d609214a4d4b43357bd9ba8a
Authentihash SHA256
7220924a787b57f757dd84b30bcd53eb11647eb65a94bfb6ffc6773aa6e6f1bf
Machine
AMD64
Version
2.00.02.00
Publisher
Avalue Technology Inc.
avalueio.sysSample 2 · HVCI FALSE
MD5
09b3d078ffa3b4ed0ad2e477a2ee341f
SHA1
54a4772212da2025bd8fb2dc913e1c4490e7a0cd
SHA256
defde359045213ae6ae278e2a92c5b4a46a74119902364c7957a38138e9c9bbd
Imphash
485f7e86663d49c68c8b5f705d310f50
Authentihash MD5
c44f40a915f2a919c0d65dd62df0bf95
Authentihash SHA1
962295f2a0a51aa7e70961609090a8d9865006be
Authentihash SHA256
4eebf3fc1a508fe0e54c061a211c44a3df641707adab16ff839187759e8d2a61
Machine
I386
Version
2.00.02.00
Publisher
Avalue Technology Inc.

Recorded command

sc.exe create avalueiosys binPath= C:\windows\temp\avalueiosys.sys type=kernel && sc.exe start avalueiosys

Elevate privileges · Privileges: kernel · OS: Windows 10

Research & references