← Back to driver explorer
Driver intelligenceVulnerableVerified

sysconp.sys

The Carbon Black Threat Analysis Unit (TAU) discovered 34 unique vulnerable drivers (237 file hashes) accepting firmware access. Six allow kernel memory access. All give full control of the devices to non-admin users. By exploiting the vulnerable drivers, an attacker without the system privilege may erase/alter firmware, and/or elevate privileges. As of the time of writing in October 2023, the filenames of the vulnerable drivers have not been made public until now.

UUID / 62f76f62-ef82-49ea-a26f-36e5727e8d83ADDED / 2023-11-02AUTHOR / Takahiro Haruyama

Known samples 2

0 recorded TRUE · 2 recorded FALSE · 0 unknown for loading despite HVCI. Results apply to individual samples.

sysconp.sysSample 1 · HVCI FALSE
MD5
bc1eeb4993a601e6f7776233028ac095
SHA1
0e1df95042081fa2408782f14ce483f0db19d5ab
SHA256
dba8db472e51edd59f0bbaf4e09df71613d4dd26fd05f14a9bc7e3fc217a78aa
Imphash
604b5bd94f1892fd9e9025ef7a2bbe54
Authentihash MD5
098c6c8b888882dc30a5ad289503d39e
Authentihash SHA1
7d7bbe8f7c7445b98b02d0ac4da109b6275331bf
Authentihash SHA256
42446592b42e34bf569a631265bcaf2a2192d424531a343a7680f52199b88462
Machine
AMD64
Version
Not recorded
Publisher
Not recorded
sysconp.sysSample 2 · HVCI FALSE
MD5
a2be99e4904264baa5649c4d4cd13a17
SHA1
ec1eafb87340b18c7ef3bc349fed1ddd5d3678f6
SHA256
df4c02beb039d15ff0c691bbc3595c9edfc1d24e783c8538a859bc5ea537188d
Imphash
604b5bd94f1892fd9e9025ef7a2bbe54
Authentihash MD5
3992bbdd329cc77ce637f85b10bc93a7
Authentihash SHA1
f02835c1c4e0d69f9ed80e97345ee6f2258c601c
Authentihash SHA256
9303894ee50d95911ccd4583b2aa5484db63de0d8f799b14854577e15914df2d
Machine
AMD64
Version
Not recorded
Publisher
Not recorded

Recorded command

sc.exe create sysconpsys binPath= C:\windows\temp\sysconpsys.sys type=kernel && sc.exe start sysconpsys

Elevate privileges · Privileges: kernel · OS: Windows 10

Research & references