← Back to driver explorer
Driver intelligenceVulnerableVerified

sepdrv3_1.sys

The Carbon Black Threat Analysis Unit (TAU) discovered 34 unique vulnerable drivers (237 file hashes) accepting firmware access. Six allow kernel memory access. All give full control of the devices to non-admin users. By exploiting the vulnerable drivers, an attacker without the system privilege may erase/alter firmware, and/or elevate privileges. As of the time of writing in October 2023, the filenames of the vulnerable drivers have not been made public until now.

UUID / 942f58d2-1300-4957-98a0-5f8d601bf55bADDED / 2023-11-02AUTHOR / Takahiro Haruyama

Known samples 1

1 recorded TRUE · 0 recorded FALSE · 0 unknown for loading despite HVCI. Results apply to individual samples.

sepdrv3_1.sysSample 1 · HVCI TRUE
MD5
29b1ddc69e89b160cc3722e5e0738fd8
SHA1
c60cf6dea446e4a52c6b1cfc2a76e9aadd954dab
SHA256
b2bc7514201727d773c09a1cfcfae793fcdbad98024251ccb510df0c269b04e6
Imphash
ee9cc2f584c2f06fbff67d484adcf426
Authentihash MD5
bf5f82976c0c5c48cb5631bf6eda8e6c
Authentihash SHA1
9d28ee1a0348c8fd0f90580fcd81a6338e372eac
Authentihash SHA256
abb507455dd1e23e91753f17d6d7a8a5d6572e288f25eb75e4cbdd2e60adae88
Machine
AMD64
Version
Not recorded
Publisher
Not recorded

Recorded command

sc.exe create sepdrv3_1sys binPath= C:\windows\temp\sepdrv3_1sys.sys type=kernel && sc.exe start sepdrv3_1sys

Elevate privileges · Privileges: kernel · OS: Windows 10

Research & references