Description Trellix HX Agent fekern.sys 34.x is affected by CVE-2025-14963. The signed FireEye 34.5.0 and 34.8.0 builds tracked here expose the \Device\fekern_00 interface. Used as a standalone BYOVD, the vulnerable driver can provide access to LSASS memory and enable local privilege escalation. A fully functioning HX Agent restricts access through tamper protection.
UUID : 8858c9c8-e570-41ed-a5cc-054d9eb51d40Created : 2026-08-31Author : Michael HaagAcknowledgement : fluffycats31 | @fluffycats31 Download
This download link contains the vulnerable driver!
Block fekern.sys across your endpoints Add this driver to your block policy in minutes with MagicSword, threat-driven application control. Free for up to 100 endpoints.
Start Blocking for Free Commands sc.exe create fekern type= kernel binPath= C:\\windows\\temp\\fekern.sys && sc.exe start fekern
Use Case Privileges Operating System Access protected process memory and elevate privileges Administrator Windows
Detections Sigma 🛡️ Expand Names
detects loading using name only
Hashes
detects loading using hashes only
Resources https://github.com/magicsword-io/LOLDrivers/issues/409 https://github.com/fluffycats31/vulnerable-drivers https://nvd.nist.gov/vuln/detail/CVE-2025-14963 https://thrive.trellix.com/s/article/000015100 CVE CVE-2025-14963 Known Vulnerable Samples Download
Certificates Expand Certificate 33000000c45021ba6ed85a72ad0000000000c4 Field Value ToBeSigned (TBS) MD5 e975b1260aeb42737a8a0bcba0d5c24e ToBeSigned (TBS) SHA1 6afd0dea6439a4fad5b95b6e38e665a46f712bb3 ToBeSigned (TBS) SHA256 6fb4e5b945142cf1513333ceb747c86a52e2fd9e8a5547b05d66c21dfbb62574 Subject C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Windows Hardware Compatibility Publisher ValidFrom 2021-06-17 17:55:59 ValidTo 2022-06-16 17:55:59 Signature 86c046c6aad742690ff7f844415b7f7cb799bf9032242efa060d27f5031ddee3a6f8ce8a04ea8760d8c80f3d7aecd8a34de975ec737b46c1691356c415471ec4a764886995244681633e929fb9ddbb7fc952a50cd5c23fa6691b732309a497f400c3a4d831f065d6e225c49abd94895990e6ab3cde4ef1a331791f737a3e8ee91f4f89b23988e85ba758c46540d9daeb24edfc2e80cd538878b0582e2a9346e17fe66cd5b45f80d8396c8b46d3d1674b6f288e98bcd6afc15b8a10d37163afb455badeca5a96bdc5cd655395208ecddc734d898980d5c3e5f50dceffabcefaa2b4470d2198e9b2b55537f941934f9eb952b7ddd601bfa7338316eee806b7db4e SignatureAlgorithmOID 1.2.840.113549.1.1.11 IsCertificateAuthority False SerialNumber 33000000c45021ba6ed85a72ad0000000000c4 Version 3
Certificate 610baac1000000000009 Field Value ToBeSigned (TBS) MD5 a569061297e8e824767dbc3184a69bea ToBeSigned (TBS) SHA1 adbb26a587a8f44b4fccaecb306f980d1c55a150 ToBeSigned (TBS) SHA256 cec1afd0e310c55c1dcc601ab8e172917706aa32fb5eaf826813547fdf02dd46 Subject C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Windows Third Party Component CA 2012 ValidFrom 2012-04-18 23:48:38 ValidTo 2027-04-18 23:58:38 Signature 5a8a67daccd5fd0d264177bf0a4678b4b3de12692b7723c2652f015fd203f461ba509d2e8c3972f36c3e6ab11e766decb7f382dcccbbc56970287366173f54ebee011648c446d91b80ae813a8d0f796d68b09eea2d3f39d3ca387ebd5e7c086e19dcc6c2f438336861e2524783e1000156d2bacb878205310a418b4ee77f5f5fed5fd3392d45eba213bffd1ec298417161165fc80a70257c59693124e471e70abb0417f79f721ec9d2bb1abe3d02fe090cb243b4591a99539396215fe0d6b72601429536ac27fdbef48577683d18bdf4be98882211865216f345ec0397107087a37043713cdbc98603170cf5735bc67de15c64edd7c548d7ed32e2d1aad3cfa7f6574e61f977eb67f288b3de00da038fd08a34373e1dd862b8d2b1f3e12f8b723b81967c6ffcec667672601b24f2a0896d5b6d002eef28dd868705c2b4b9e5be64c22af24a155c98e2c42785ff52e3627e0fb2020bd766c70ab2d33d200414503259830a7d9bed5a38120152ba2f5e20728e4af1fde771028c3be107bec973f4dd47d8b4efb4a4b330b9893e76cab90098567eabea8ab8a5d038ab6977130b142fe9aa411ff7babd3a2b348aee0aab63e663f788248e200d2b3b9de3c24952ac9f1f0e393b5dd46e506ae67d523aaa7c3315290d265e0158a74ea93d7a846f743f609fe4324f3600af6d71d33ea646655f8174f1fec171da4ca0415a82ddf11f SignatureAlgorithmOID 1.2.840.113549.1.1.11 IsCertificateAuthority True SerialNumber 610baac1000000000009 Version 3
Imports Expand ntoskrnl.exe FLTMGR.SYS fwpkclnt.sys Imported Functions Expand KeSetEvent KeReleaseSpinLock KeDelayExecutionThread KeAcquireSpinLockRaiseToDpc _wcsnicmp RtlDeleteElementGenericTableAvl RtlInsertElementGenericTableAvl IoGetRelatedDeviceObject IoReleaseRemoveLockEx MmMapLockedPagesSpecifyCache RtlInitializeGenericTableAvl RtlLookupElementGenericTableAvl RtlEnumerateGenericTableWithoutSplayingAvl _vsnprintf ExAcquireResourceExclusiveLite KeLeaveCriticalRegion KeEnterCriticalRegion ExReleaseResourceLite ExDeleteResourceLite ExInitializeResourceLite ExAcquireSharedStarveExclusive KeBugCheckEx RtlCreateSecurityDescriptor RtlLengthSid KeStackAttachProcess ObOpenObjectByPointer ZwOpenSection MmGetPhysicalMemoryRanges IoCreateDevice IoInitializeRemoveLockEx PsSetLoadImageNotifyRoutine PsRemoveCreateThreadNotifyRoutine PsLookupProcessByProcessId PsGetProcessCreateTimeQuadPart PsSetCreateThreadNotifyRoutine PsSetCreateProcessNotifyRoutine ExAcquireResourceSharedLite PsRemoveLoadImageNotifyRoutine PsThreadType CmRegisterCallback CmUnRegisterCallback IoThreadToProcess ExInitializeNPagedLookasideList ExpInterlockedPushEntrySList _snprintf ExpInterlockedPopEntrySList ExQueryDepthSList IoReleaseCancelSpinLock PsGetProcessId ExDeleteNPagedLookasideList ObfDereferenceObject RtlHashUnicodeString RtlEnumerateGenericTableAvl RtlUpcaseUnicodeString FsRtlIsNameInExpression RtlFreeUnicodeString ZwReadFile ZwOpenProcessTokenEx ObQueryNameString IoFileObjectType ZwCreateFile ZwQueryInformationProcess ZwQueryInformationToken ZwQueryInformationFile IoGetDeviceProperty ObReferenceObjectByPointer ExReleaseFastMutex ExAcquireFastMutex KeInitializeEvent ZwSetInformationFile RtlCompareUnicodeString vDbgPrintEx strncpy PsLookupThreadByThreadId wcschr IoGetTopLevelIrp PsGetCurrentThreadId KeAcquireInStackQueuedSpinLockAtDpcLevel KeReleaseInStackQueuedSpinLock KeAcquireInStackQueuedSpinLock PsCreateSystemThread KeWaitForSingleObject KeReleaseInStackQueuedSpinLockFromDpcLevel _wcsicmp KeInitializeApc KeInsertQueueApc IoIs32bitProcess RtlEqualUnicodeString ZwFreeVirtualMemory PsIsThreadTerminating ZwAllocateVirtualMemory PsReferencePrimaryToken PsInitialSystemProcess PsDereferencePrimaryToken ZwQueryDirectoryFile SeQueryInformationToken RtlPrefixUnicodeString IoCsqInsertIrp IoCsqInitialize IoCsqRemoveNextIrp wcsncpy RtlCopyUnicodeString PsGetCurrentProcessId IoCreateSymbolicLink SeExports RtlCompareMemory ZwSetSecurityObject ObReferenceObjectByHandle IoReleaseRemoveLockAndWaitEx IofCompleteRequest ZwClose ExEventObjectType tolower ExInitializeLookasideListEx ExDeleteLookasideListEx strncmp IoGetCurrentProcess ZwUnmapViewOfSection MmGetPhysicalAddress RtlAddAccessAllowedAce KeUnstackDetachProcess MmHighestUserAddress RtlGetVersion MmGetSystemRoutineAddress IoDeleteDevice RtlInitUnicodeString ZwMapViewOfSection RtlSetDaclSecurityDescriptor RtlCreateAcl IoWMIWriteEvent ExFreePoolWithTag IoDeleteSymbolicLink PsProcessType IoWMIRegistrationControl IoAcquireRemoveLockEx ProbeForRead RtlIsGenericTableEmptyAvl ExAllocatePoolWithTag __C_specific_handler _local_unwind FltGetRequestorProcessIdEx FltQueryInformationFile FltGetFileNameInformation FltUnregisterFilter FltRegisterFilter FltReleaseFileNameInformation FltStartFiltering FltObjectDereference FltGetStreamHandleContext FltSetStreamHandleContext FltAllocatePoolAlignedWithTag FltGetVolumeProperties FltGetVolumeFromInstance FltReleaseContext FltAllocateContext FltParseFileNameInformation FltFreePoolAlignedWithTag FltReadFile FwpmTransactionBegin0 FwpmFilterAdd0 FwpmProviderDeleteByKey0 FwpmEngineOpen0 FwpmTransactionAbort0 FwpsCalloutRegister0 FwpmBfeStateGet0 FwpmProviderAdd0 FwpmBfeStateSubscribeChanges0 FwpmCalloutAdd0 FwpmTransactionCommit0 FwpmSubLayerAdd0 FwpsFlowAssociateContext0 FwpmBfeStateUnsubscribeChanges0 FwpsCalloutUnregisterById0 FwpmFilterDeleteById0 FwpsCopyStreamDataToBuffer0 FwpmSubLayerDeleteByKey0 FwpmCalloutDeleteById0 FwpsFlowRemoveContext0 FwpmEngineClose0 Exported Functions Expand Sections Expand .text .rdata .data .pdata PAGE INIT .rsrc .reloc Signature Expand {
"Certificates": [
{
"CertificateType": "Leaf (Code Signing)",
"IsCA": false,
"IsCertificateAuthority": false,
"IsCodeSigning": true,
"SerialNumber": "33000000c45021ba6ed85a72ad0000000000c4",
"Signature": "86c046c6aad742690ff7f844415b7f7cb799bf9032242efa060d27f5031ddee3a6f8ce8a04ea8760d8c80f3d7aecd8a34de975ec737b46c1691356c415471ec4a764886995244681633e929fb9ddbb7fc952a50cd5c23fa6691b732309a497f400c3a4d831f065d6e225c49abd94895990e6ab3cde4ef1a331791f737a3e8ee91f4f89b23988e85ba758c46540d9daeb24edfc2e80cd538878b0582e2a9346e17fe66cd5b45f80d8396c8b46d3d1674b6f288e98bcd6afc15b8a10d37163afb455badeca5a96bdc5cd655395208ecddc734d898980d5c3e5f50dceffabcefaa2b4470d2198e9b2b55537f941934f9eb952b7ddd601bfa7338316eee806b7db4e",
"SignatureAlgorithmOID": "1.2.840.113549.1.1.11",
"Subject": "C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Windows Hardware Compatibility Publisher",
"TBS": {
"MD5": "e975b1260aeb42737a8a0bcba0d5c24e",
"SHA1": "6afd0dea6439a4fad5b95b6e38e665a46f712bb3",
"SHA256": "6fb4e5b945142cf1513333ceb747c86a52e2fd9e8a5547b05d66c21dfbb62574",
"SHA384": "29cf23d8694596226f5be6abfce3eb72d702dcb8f4557ef6c9a17b6cc8689b763ed21b885d57ccef2156f3ae16902629"
},
"ValidFrom": "2021-06-17 17:55:59",
"ValidTo": "2022-06-16 17:55:59",
"Version": 3
},
{
"CertificateType": "CA",
"IsCA": true,
"IsCertificateAuthority": true,
"IsCodeSigning": false,
"SerialNumber": "610baac1000000000009",
"Signature": "5a8a67daccd5fd0d264177bf0a4678b4b3de12692b7723c2652f015fd203f461ba509d2e8c3972f36c3e6ab11e766decb7f382dcccbbc56970287366173f54ebee011648c446d91b80ae813a8d0f796d68b09eea2d3f39d3ca387ebd5e7c086e19dcc6c2f438336861e2524783e1000156d2bacb878205310a418b4ee77f5f5fed5fd3392d45eba213bffd1ec298417161165fc80a70257c59693124e471e70abb0417f79f721ec9d2bb1abe3d02fe090cb243b4591a99539396215fe0d6b72601429536ac27fdbef48577683d18bdf4be98882211865216f345ec0397107087a37043713cdbc98603170cf5735bc67de15c64edd7c548d7ed32e2d1aad3cfa7f6574e61f977eb67f288b3de00da038fd08a34373e1dd862b8d2b1f3e12f8b723b81967c6ffcec667672601b24f2a0896d5b6d002eef28dd868705c2b4b9e5be64c22af24a155c98e2c42785ff52e3627e0fb2020bd766c70ab2d33d200414503259830a7d9bed5a38120152ba2f5e20728e4af1fde771028c3be107bec973f4dd47d8b4efb4a4b330b9893e76cab90098567eabea8ab8a5d038ab6977130b142fe9aa411ff7babd3a2b348aee0aab63e663f788248e200d2b3b9de3c24952ac9f1f0e393b5dd46e506ae67d523aaa7c3315290d265e0158a74ea93d7a846f743f609fe4324f3600af6d71d33ea646655f8174f1fec171da4ca0415a82ddf11f",
"SignatureAlgorithmOID": "1.2.840.113549.1.1.11",
"Subject": "C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Windows Third Party Component CA 2012",
"TBS": {
"MD5": "a569061297e8e824767dbc3184a69bea",
"SHA1": "adbb26a587a8f44b4fccaecb306f980d1c55a150",
"SHA256": "cec1afd0e310c55c1dcc601ab8e172917706aa32fb5eaf826813547fdf02dd46",
"SHA384": "e947cac936803f5683196e4ff1b259096073395d0b908522ddce90d57597c9f7b57f7ddcdbe021ba863d843c340da8ba"
},
"ValidFrom": "2012-04-18 23:48:38",
"ValidTo": "2027-04-18 23:58:38",
"Version": 3
}
],
"CertificatesInfo": "",
"Signer": [
{
"Issuer": "C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Windows Third Party Component CA 2012",
"SerialNumber": "33000000c45021ba6ed85a72ad0000000000c4",
"Version": 1
}
],
"SignerInfo": ""
}
Download
Certificates Expand Certificate 33000000f3158ea57d1c559f290000000000f3 Field Value ToBeSigned (TBS) MD5 8d4476692bcda36ed89244b94bd705f0 ToBeSigned (TBS) SHA1 ce72176d5cad611366e13a9a997ad7ecc7eb815f ToBeSigned (TBS) SHA256 dd1db9c0e7e50040ac6c586c1b6fd479cef240c064473373f75fbeb3e04ff972 Subject C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Windows Hardware Compatibility Publisher ValidFrom 2023-01-12 19:14:51 ValidTo 2023-12-15 19:14:51 Signature 04d1261b735b38b551b427cf9a295d4eb18edd92de14079aa33a10511ee6d262938b29ae208f96be64a80e2967fb8d7aa5750613901a9da6a82935398175482096430c9acecb55ee2c5468d119f467378c18251a8fe01e9d7b79bce903ccb7afb227e2d0abee00bd9fd6bbbbd67c014888dc46f3efa912d4576f7ca9980957609cd21fbd51815cb11bee95fa780498d905e866bc1a604e407ee0d97a105bcc8e600200b19b9c3a56cb3918047f21ba9ee2228b46b8e5c8b456ba65e6f0c40d28294b654761660e9d14948866c3f0f65f028e47641059d3f195812e871362128bcefb901d5aeace862e3d683b291d65c138138ea1335fe3552f4c46a7f7b0c6e5 SignatureAlgorithmOID 1.2.840.113549.1.1.11 IsCertificateAuthority False SerialNumber 33000000f3158ea57d1c559f290000000000f3 Version 3
Certificate 610baac1000000000009 Field Value ToBeSigned (TBS) MD5 a569061297e8e824767dbc3184a69bea ToBeSigned (TBS) SHA1 adbb26a587a8f44b4fccaecb306f980d1c55a150 ToBeSigned (TBS) SHA256 cec1afd0e310c55c1dcc601ab8e172917706aa32fb5eaf826813547fdf02dd46 Subject C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Windows Third Party Component CA 2012 ValidFrom 2012-04-18 23:48:38 ValidTo 2027-04-18 23:58:38 Signature 5a8a67daccd5fd0d264177bf0a4678b4b3de12692b7723c2652f015fd203f461ba509d2e8c3972f36c3e6ab11e766decb7f382dcccbbc56970287366173f54ebee011648c446d91b80ae813a8d0f796d68b09eea2d3f39d3ca387ebd5e7c086e19dcc6c2f438336861e2524783e1000156d2bacb878205310a418b4ee77f5f5fed5fd3392d45eba213bffd1ec298417161165fc80a70257c59693124e471e70abb0417f79f721ec9d2bb1abe3d02fe090cb243b4591a99539396215fe0d6b72601429536ac27fdbef48577683d18bdf4be98882211865216f345ec0397107087a37043713cdbc98603170cf5735bc67de15c64edd7c548d7ed32e2d1aad3cfa7f6574e61f977eb67f288b3de00da038fd08a34373e1dd862b8d2b1f3e12f8b723b81967c6ffcec667672601b24f2a0896d5b6d002eef28dd868705c2b4b9e5be64c22af24a155c98e2c42785ff52e3627e0fb2020bd766c70ab2d33d200414503259830a7d9bed5a38120152ba2f5e20728e4af1fde771028c3be107bec973f4dd47d8b4efb4a4b330b9893e76cab90098567eabea8ab8a5d038ab6977130b142fe9aa411ff7babd3a2b348aee0aab63e663f788248e200d2b3b9de3c24952ac9f1f0e393b5dd46e506ae67d523aaa7c3315290d265e0158a74ea93d7a846f743f609fe4324f3600af6d71d33ea646655f8174f1fec171da4ca0415a82ddf11f SignatureAlgorithmOID 1.2.840.113549.1.1.11 IsCertificateAuthority True SerialNumber 610baac1000000000009 Version 3
Imports Expand ntoskrnl.exe FLTMGR.SYS fwpkclnt.sys Imported Functions Expand KeSetEvent KeReleaseSpinLock KeDelayExecutionThread KeAcquireSpinLockRaiseToDpc _wcsnicmp RtlDeleteElementGenericTableAvl RtlInsertElementGenericTableAvl IoGetRelatedDeviceObject IoReleaseRemoveLockEx MmMapLockedPagesSpecifyCache RtlInitializeGenericTableAvl RtlLookupElementGenericTableAvl RtlEnumerateGenericTableWithoutSplayingAvl _vsnprintf ExAcquireResourceExclusiveLite KeLeaveCriticalRegion KeEnterCriticalRegion ExReleaseResourceLite ExDeleteResourceLite ExInitializeResourceLite ExAcquireSharedStarveExclusive KeBugCheckEx RtlCreateSecurityDescriptor RtlLengthSid KeStackAttachProcess ObOpenObjectByPointer ZwOpenSection MmGetPhysicalMemoryRanges IoCreateDevice IoInitializeRemoveLockEx PsSetLoadImageNotifyRoutine PsRemoveCreateThreadNotifyRoutine PsLookupProcessByProcessId PsGetProcessCreateTimeQuadPart PsSetCreateThreadNotifyRoutine PsSetCreateProcessNotifyRoutine ExAcquireResourceSharedLite PsRemoveLoadImageNotifyRoutine PsThreadType CmRegisterCallback CmUnRegisterCallback IoThreadToProcess ExInitializeNPagedLookasideList ExpInterlockedPushEntrySList _snprintf ExpInterlockedPopEntrySList ExQueryDepthSList IoReleaseCancelSpinLock PsGetProcessId ExDeleteNPagedLookasideList ObfDereferenceObject RtlHashUnicodeString RtlEnumerateGenericTableAvl RtlUpcaseUnicodeString FsRtlIsNameInExpression RtlFreeUnicodeString ZwReadFile ZwOpenProcessTokenEx ObQueryNameString IoFileObjectType ZwCreateFile ZwQueryInformationProcess ZwQueryInformationToken ZwQueryInformationFile IoGetDeviceProperty ObReferenceObjectByPointer ExReleaseFastMutex ExAcquireFastMutex KeInitializeEvent ZwSetInformationFile RtlCompareUnicodeString vDbgPrintEx strncpy PsLookupThreadByThreadId wcschr IoGetTopLevelIrp PsGetCurrentThreadId KeAcquireInStackQueuedSpinLockAtDpcLevel KeReleaseInStackQueuedSpinLock KeAcquireInStackQueuedSpinLock PsCreateSystemThread KeWaitForSingleObject KeReleaseInStackQueuedSpinLockFromDpcLevel _wcsicmp KeInitializeApc KeInsertQueueApc IoIs32bitProcess RtlEqualUnicodeString ZwFreeVirtualMemory PsIsThreadTerminating ZwAllocateVirtualMemory PsReferencePrimaryToken PsInitialSystemProcess PsDereferencePrimaryToken ZwQueryDirectoryFile SeQueryInformationToken RtlPrefixUnicodeString IoCsqInsertIrp IoCsqInitialize IoCsqRemoveNextIrp wcsncpy RtlCopyUnicodeString PsGetCurrentProcessId IoCreateSymbolicLink SeExports RtlCompareMemory ZwSetSecurityObject ObReferenceObjectByHandle IoReleaseRemoveLockAndWaitEx IofCompleteRequest ZwClose ExEventObjectType tolower ExInitializeLookasideListEx ExDeleteLookasideListEx strncmp IoGetCurrentProcess ZwUnmapViewOfSection MmGetPhysicalAddress RtlAddAccessAllowedAce KeUnstackDetachProcess MmHighestUserAddress RtlGetVersion MmGetSystemRoutineAddress IoDeleteDevice RtlInitUnicodeString ZwMapViewOfSection RtlSetDaclSecurityDescriptor RtlCreateAcl IoWMIWriteEvent ExFreePoolWithTag IoDeleteSymbolicLink PsProcessType IoWMIRegistrationControl IoAcquireRemoveLockEx ProbeForRead RtlIsGenericTableEmptyAvl ExAllocatePoolWithTag __C_specific_handler _local_unwind FltGetRequestorProcessIdEx FltQueryInformationFile FltGetFileNameInformation FltUnregisterFilter FltRegisterFilter FltReleaseFileNameInformation FltStartFiltering FltObjectDereference FltGetStreamHandleContext FltSetStreamHandleContext FltAllocatePoolAlignedWithTag FltGetVolumeProperties FltGetVolumeFromInstance FltReleaseContext FltAllocateContext FltParseFileNameInformation FltFreePoolAlignedWithTag FltReadFile FwpmTransactionBegin0 FwpmFilterAdd0 FwpmProviderDeleteByKey0 FwpmEngineOpen0 FwpmTransactionAbort0 FwpsCalloutRegister0 FwpmBfeStateGet0 FwpmProviderAdd0 FwpmBfeStateSubscribeChanges0 FwpmCalloutAdd0 FwpmTransactionCommit0 FwpmSubLayerAdd0 FwpsFlowAssociateContext0 FwpmBfeStateUnsubscribeChanges0 FwpsCalloutUnregisterById0 FwpmFilterDeleteById0 FwpsCopyStreamDataToBuffer0 FwpmSubLayerDeleteByKey0 FwpmCalloutDeleteById0 FwpsFlowRemoveContext0 FwpmEngineClose0 Exported Functions Expand Sections Expand .text .rdata .data .pdata PAGE INIT .rsrc .reloc Signature Expand {
"Certificates": [
{
"CertificateType": "Leaf (Code Signing)",
"IsCA": false,
"IsCertificateAuthority": false,
"IsCodeSigning": true,
"SerialNumber": "33000000c45021ba6ed85a72ad0000000000c4",
"Signature": "86c046c6aad742690ff7f844415b7f7cb799bf9032242efa060d27f5031ddee3a6f8ce8a04ea8760d8c80f3d7aecd8a34de975ec737b46c1691356c415471ec4a764886995244681633e929fb9ddbb7fc952a50cd5c23fa6691b732309a497f400c3a4d831f065d6e225c49abd94895990e6ab3cde4ef1a331791f737a3e8ee91f4f89b23988e85ba758c46540d9daeb24edfc2e80cd538878b0582e2a9346e17fe66cd5b45f80d8396c8b46d3d1674b6f288e98bcd6afc15b8a10d37163afb455badeca5a96bdc5cd655395208ecddc734d898980d5c3e5f50dceffabcefaa2b4470d2198e9b2b55537f941934f9eb952b7ddd601bfa7338316eee806b7db4e",
"SignatureAlgorithmOID": "1.2.840.113549.1.1.11",
"Subject": "C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Windows Hardware Compatibility Publisher",
"TBS": {
"MD5": "e975b1260aeb42737a8a0bcba0d5c24e",
"SHA1": "6afd0dea6439a4fad5b95b6e38e665a46f712bb3",
"SHA256": "6fb4e5b945142cf1513333ceb747c86a52e2fd9e8a5547b05d66c21dfbb62574",
"SHA384": "29cf23d8694596226f5be6abfce3eb72d702dcb8f4557ef6c9a17b6cc8689b763ed21b885d57ccef2156f3ae16902629"
},
"ValidFrom": "2021-06-17 17:55:59",
"ValidTo": "2022-06-16 17:55:59",
"Version": 3
},
{
"CertificateType": "CA",
"IsCA": true,
"IsCertificateAuthority": true,
"IsCodeSigning": false,
"SerialNumber": "610baac1000000000009",
"Signature": "5a8a67daccd5fd0d264177bf0a4678b4b3de12692b7723c2652f015fd203f461ba509d2e8c3972f36c3e6ab11e766decb7f382dcccbbc56970287366173f54ebee011648c446d91b80ae813a8d0f796d68b09eea2d3f39d3ca387ebd5e7c086e19dcc6c2f438336861e2524783e1000156d2bacb878205310a418b4ee77f5f5fed5fd3392d45eba213bffd1ec298417161165fc80a70257c59693124e471e70abb0417f79f721ec9d2bb1abe3d02fe090cb243b4591a99539396215fe0d6b72601429536ac27fdbef48577683d18bdf4be98882211865216f345ec0397107087a37043713cdbc98603170cf5735bc67de15c64edd7c548d7ed32e2d1aad3cfa7f6574e61f977eb67f288b3de00da038fd08a34373e1dd862b8d2b1f3e12f8b723b81967c6ffcec667672601b24f2a0896d5b6d002eef28dd868705c2b4b9e5be64c22af24a155c98e2c42785ff52e3627e0fb2020bd766c70ab2d33d200414503259830a7d9bed5a38120152ba2f5e20728e4af1fde771028c3be107bec973f4dd47d8b4efb4a4b330b9893e76cab90098567eabea8ab8a5d038ab6977130b142fe9aa411ff7babd3a2b348aee0aab63e663f788248e200d2b3b9de3c24952ac9f1f0e393b5dd46e506ae67d523aaa7c3315290d265e0158a74ea93d7a846f743f609fe4324f3600af6d71d33ea646655f8174f1fec171da4ca0415a82ddf11f",
"SignatureAlgorithmOID": "1.2.840.113549.1.1.11",
"Subject": "C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Windows Third Party Component CA 2012",
"TBS": {
"MD5": "a569061297e8e824767dbc3184a69bea",
"SHA1": "adbb26a587a8f44b4fccaecb306f980d1c55a150",
"SHA256": "cec1afd0e310c55c1dcc601ab8e172917706aa32fb5eaf826813547fdf02dd46",
"SHA384": "e947cac936803f5683196e4ff1b259096073395d0b908522ddce90d57597c9f7b57f7ddcdbe021ba863d843c340da8ba"
},
"ValidFrom": "2012-04-18 23:48:38",
"ValidTo": "2027-04-18 23:58:38",
"Version": 3
}
],
"CertificatesInfo": "",
"Signer": [
{
"Issuer": "C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Windows Third Party Component CA 2012",
"SerialNumber": "33000000c45021ba6ed85a72ad0000000000c4",
"Version": 1
}
],
"SignerInfo": ""
}
source
last_updated: 2026-08-31