← Back to driver explorer
Driver intelligenceVulnerableVerified

tdeio64.sys

The Carbon Black Threat Analysis Unit (TAU) discovered 34 unique vulnerable drivers (237 file hashes) accepting firmware access. Six allow kernel memory access. All give full control of the devices to non-admin users. By exploiting the vulnerable drivers, an attacker without the system privilege may erase/alter firmware, and/or elevate privileges. As of the time of writing in October 2023, the filenames of the vulnerable drivers have not been made public until now.

UUID / 4f47c65e-2e73-4855-813a-5a823ae845a8ADDED / 2023-11-02AUTHOR / Takahiro Haruyama

Known samples 2

0 recorded TRUE · 2 recorded FALSE · 0 unknown for loading despite HVCI. Results apply to individual samples.

tdeio64.sysSample 1 · HVCI FALSE
MD5
97e90c869b5b0f493b833710931c39ed
SHA1
f1b3bdc3beb2dca19940d53eb5a0aed85b807e30
SHA256
1076504a145810dfe331324007569b95d0310ac1e08951077ac3baf668b2a486
Imphash
8211bd4f00a3d9928a11a6ac3329fc46
Authentihash MD5
6ff943f654668582c1f1afa011932d7a
Authentihash SHA1
4cac09246c22324368f367e03550734a281471c5
Authentihash SHA256
c8a34012c22a650972b9ecad988d346c8670bcd51ea2dd3ab7fe4562e117f1b9
Machine
AMD64
Version
Not recorded
Publisher
Not recorded
tdeio64.sysSample 2 · HVCI FALSE
MD5
f766a9bb7cd46ba8c871484058f908f0
SHA1
24b3f962587b0062ac9a1ec71bcc3836b12306d2
SHA256
13ae4d9dcacba8133d8189e59d9352272e15629e6bca580c32aff9810bd96e44
Imphash
8211bd4f00a3d9928a11a6ac3329fc46
Authentihash MD5
6ff943f654668582c1f1afa011932d7a
Authentihash SHA1
4cac09246c22324368f367e03550734a281471c5
Authentihash SHA256
c8a34012c22a650972b9ecad988d346c8670bcd51ea2dd3ab7fe4562e117f1b9
Machine
AMD64
Version
Not recorded
Publisher
Not recorded

Recorded command

sc.exe create tdeio64sys binPath= C:\windows\temp\tdeio64sys.sys type=kernel && sc.exe start tdeio64sys

Elevate privileges · Privileges: kernel · OS: Windows 10

Research & references