QIOMem.sys
QIOMem.sys is the Generic IO & Memory Access driver included with Toshiba and Dynabook password utilities. It binds to ACPI\QCI0701; on systems without that firmware device, the public proof of concept creates a matching software PnP device to trigger loading of an already-installed driver package. Six IOCTLs (0x08012000 through 0x08012014) pass an unvalidated 32-bit physical address to MmMapIoSpace, allowing a low-privileged process to read or write one, two, or four bytes of physical memory below 4 GiB.
Known samples 1
0 recorded TRUE · 0 recorded FALSE · 1 unknown for loading despite HVCI. Results apply to individual samples.
QIOMem.sysSample 1 · HVCI unknown
- MD5
43252ab49c9a43d22aa583c15e96f7b7- SHA1
ee37a040b6ec7882b4e240e70da67bc0900fd799- SHA256
6abd8d0d541bcf9e257c65122216b1d2ae92cbf8a3a3cb7ce340846e66c449ca- Imphash
25adb8efbc15f349a1e3578fb2b9bf8f- Authentihash MD5
e7d3aa85b456b305803472f276dd29f0- Authentihash SHA1
927108063af531702e54c89d3beb395f715f9706- Authentihash SHA256
de7b59f676aadcc0173e5a8d6b22f74f6a7f9c0ed906e5cc5f3e0fd821adb813- Machine
- AMD64
- Version
- 5.0.0.0
- Publisher
- Microsoft Windows Hardware Compatibility Publisher
Recorded command
acpi.exeRead or write physical memory from a low-privileged process. · Privileges: User · OS: Windows 7, Windows 8, Windows 8.1, Windows 10, Windows 11
Research & references
Acknowledgement: Akshit Yadav @valium007

