← Back to driver explorer
Driver intelligenceVulnerableVerified

bootrepair.sys

BootRepair.sys is a legitimate Lenovo kernel driver shipped with Lenovo PC Manager (signed by LENOVO via Symantec Class 3 SHA256 Code Signing CA, compile date 2018-01-03). The driver creates a device object at \\.\BootRepair with no DACL restrictions, so any local user can open a handle. The IRP_MJ_DEVICE_CONTROL dispatcher accepts IOCTL 0x222014 with a 4-byte DWORD input (target PID) and chains PsLookupProcessByProcessId -> ObOpenObjectByPointer -> ZwTerminateProcess against the supplied PID, with no caller validation. Because the kernel-mode caller bypasses user-mode access checks, the primitive can terminate any process on the system including PPL-protected AV/EDR processes. The driver also imports ZwCreateKey / ZwSetValueKey / ZwQueryValueKey (registry access for the boot-repair feature), PsCreateSystemThread / IoRegisterShutdownNotification, and KeBugCheckEx.

UUID / 7cc0a40d-7902-4400-9fc4-0070053991cbADDED / 2026-05-19AUTHOR / Michael Haag

Known samples 1

0 recorded TRUE · 1 recorded FALSE · 0 unknown for loading despite HVCI. Results apply to individual samples.

BootRepair.sysSample 1 · HVCI FALSE
MD5
82699276b0f59a2304120a6baaf64a6b
SHA1
87903559afa09a0dfe251598c14e58124bddde1d
SHA256
5ab36c116767eaae53a466fbc2dae7cfd608ed77721f65e83312037fbd57c946
Imphash
e1e5f6628200ed317625c64c1d1819aa
Authentihash MD5
b1b3128961d3cb0c2fac16215719e8f6
Authentihash SHA1
f8b69357a559dd51090026ce7d7999eb993ecc6c
Authentihash SHA256
498adc5cd35a5bab1fb935dc93158b297b0882b80206bbb74d003df0f1c8c037
Machine
AMD64
Version
2.5.30.11281
Publisher
LENOVO

Recorded command

sc.exe create BootRepair binPath=C:\windows\temp\BootRepair.sys type=kernel && sc.exe start BootRepair

Terminate arbitrary processes from kernel mode (including PPL-protected AV/EDR processes) via an unauthenticated IOCTL handler. · Privileges: kernel · OS: Windows 10

Research & references

Acknowledgement: Jehad Abudagga @j3h4ck