bootrepair.sys
BootRepair.sys is a legitimate Lenovo kernel driver shipped with Lenovo PC Manager (signed by LENOVO via Symantec Class 3 SHA256 Code Signing CA, compile date 2018-01-03). The driver creates a device object at \\.\BootRepair with no DACL restrictions, so any local user can open a handle. The IRP_MJ_DEVICE_CONTROL dispatcher accepts IOCTL 0x222014 with a 4-byte DWORD input (target PID) and chains PsLookupProcessByProcessId -> ObOpenObjectByPointer -> ZwTerminateProcess against the supplied PID, with no caller validation. Because the kernel-mode caller bypasses user-mode access checks, the primitive can terminate any process on the system including PPL-protected AV/EDR processes. The driver also imports ZwCreateKey / ZwSetValueKey / ZwQueryValueKey (registry access for the boot-repair feature), PsCreateSystemThread / IoRegisterShutdownNotification, and KeBugCheckEx.
Known samples 1
0 recorded TRUE · 1 recorded FALSE · 0 unknown for loading despite HVCI. Results apply to individual samples.
BootRepair.sysSample 1 · HVCI FALSE
- MD5
82699276b0f59a2304120a6baaf64a6b- SHA1
87903559afa09a0dfe251598c14e58124bddde1d- SHA256
5ab36c116767eaae53a466fbc2dae7cfd608ed77721f65e83312037fbd57c946- Imphash
e1e5f6628200ed317625c64c1d1819aa- Authentihash MD5
b1b3128961d3cb0c2fac16215719e8f6- Authentihash SHA1
f8b69357a559dd51090026ce7d7999eb993ecc6c- Authentihash SHA256
498adc5cd35a5bab1fb935dc93158b297b0882b80206bbb74d003df0f1c8c037- Machine
- AMD64
- Version
- 2.5.30.11281
- Publisher
- LENOVO
Recorded command
sc.exe create BootRepair binPath=C:\windows\temp\BootRepair.sys type=kernel && sc.exe start BootRepairTerminate arbitrary processes from kernel mode (including PPL-protected AV/EDR processes) via an unauthenticated IOCTL handler. · Privileges: kernel · OS: Windows 10
Research & references
Acknowledgement: Jehad Abudagga @j3h4ck

