← Back to driver explorer
Driver intelligenceVulnerableVerified

nvaudio.sys

The Carbon Black Threat Analysis Unit (TAU) discovered 34 unique vulnerable drivers (237 file hashes) accepting firmware access. Six allow kernel memory access. All give full control of the devices to non-admin users. By exploiting the vulnerable drivers, an attacker without the system privilege may erase/alter firmware, and/or elevate privileges. As of the time of writing in October 2023, the filenames of the vulnerable drivers have not been made public until now.

UUID / 837ad058-65f4-4b75-8f21-b842e48db8a5ADDED / 2023-11-02AUTHOR / Takahiro Haruyama

Known samples 1

0 recorded TRUE · 1 recorded FALSE · 0 unknown for loading despite HVCI. Results apply to individual samples.

nvaudio.sysSample 1 · HVCI FALSE
MD5
b2600502a5b962b8cdfac2ead24b17b4
SHA1
bda102afbc60f3f3c5bcbd5390ffbbbb89170b9c
SHA256
b0dcdbdc62949c981c4fc04ccea64be008676d23506fc05637d9686151a4b77f
Imphash
f475387e3959dbea86854d61602db136
Authentihash MD5
8b46a9553a2d586084c114be70b5367f
Authentihash SHA1
0fb1d0ef14ab73fcb4c62043859064cc5f9f88c2
Authentihash SHA256
6b3196a346973837242d92f3a0ff7bdc2485075d51de0b53650e4ef7348c7a83
Machine
AMD64
Version
7.00.00
Publisher
NVidia Corp.

Recorded command

sc.exe create nvaudiosys binPath= C:\windows\temp\nvaudiosys.sys type=kernel && sc.exe start nvaudiosys

Elevate privileges · Privileges: kernel · OS: Windows 10

Research & references