← Back to driver explorer
Driver intelligenceVulnerableVerified

QIOMem.sys

QIOMem.sys is the Generic IO & Memory Access driver included with Toshiba and Dynabook password utilities. It binds to ACPI\QCI0701; on systems without that firmware device, the public proof of concept creates a matching software PnP device to trigger loading of an already-installed driver package. Six IOCTLs (0x08012000 through 0x08012014) pass an unvalidated 32-bit physical address to MmMapIoSpace, allowing a low-privileged process to read or write one, two, or four bytes of physical memory below 4 GiB.

UUID / 6eca187c-8fb2-4eae-9c80-fd9ef9d8c91eADDED / 2026-07-10AUTHOR / valium

Known samples 1

0 recorded TRUE · 0 recorded FALSE · 1 unknown for loading despite HVCI. Results apply to individual samples.

QIOMem.sysSample 1 · HVCI unknown
MD5
43252ab49c9a43d22aa583c15e96f7b7
SHA1
ee37a040b6ec7882b4e240e70da67bc0900fd799
SHA256
6abd8d0d541bcf9e257c65122216b1d2ae92cbf8a3a3cb7ce340846e66c449ca
Imphash
25adb8efbc15f349a1e3578fb2b9bf8f
Authentihash MD5
e7d3aa85b456b305803472f276dd29f0
Authentihash SHA1
927108063af531702e54c89d3beb395f715f9706
Authentihash SHA256
de7b59f676aadcc0173e5a8d6b22f74f6a7f9c0ed906e5cc5f3e0fd821adb813
Machine
AMD64
Version
5.0.0.0
Publisher
Microsoft Windows Hardware Compatibility Publisher

Recorded command

acpi.exe

Read or write physical memory from a low-privileged process. · Privileges: User · OS: Windows 7, Windows 8, Windows 8.1, Windows 10, Windows 11

Research & references

Acknowledgement: Akshit Yadav @valium007