← Back to driver explorer
Driver intelligenceVulnerableVerified
hw.sys
Northwave Cyber Security contributed this driver based on in-house research. The driver has a CVSSv3 score of 8.8, indicating a privilege escalation impact. This vulnerability could potentially be exploited for privilege escalation or other malicious activities.
Known samples 1
0 recorded TRUE · 1 recorded FALSE · 0 unknown for loading despite HVCI. Results apply to individual samples.
hw.sysSample 1 · HVCI FALSE
- MD5
9347fbeeaf917fc4a1d64a0b4d61187a- SHA1
01e74172e10d8b5f589e26ee8e3e4aec485edc6f- SHA256
0483b32f9544e9c3cc3f206e7bc983ea83f5a9ca44864f2af9b8fc10ff45949f- Imphash
a70bfdb391d295cb610248955a594dbd- Authentihash MD5
61ecd10a6dab25d4627ec22f5a924180- Authentihash SHA1
f65f4e4ae18e2497686d023fa42b7269c646f662- Authentihash SHA256
b0ed869a98c4cc2fc84deacb91ab87ca7657f0aea3e1c23234263e99237712fb- Machine
- AMD64
- Version
- 5.0.2.0
- Publisher
- Marvin Test Solutions, Inc.
Recorded command
sc.exe create hw binPath=C:\windows\temp\hw.sys type=kernel && sc.exe start hwElevate privileges · Privileges: kernel · OS: Windows 10
Research & references
Acknowledgement: Northwave Cyber Security

