← Back to driver explorer
Driver intelligenceVulnerableVerified

DriversCloud_amd64.sys

CYBELSOFT DriversCloud_amd64.sys exposes 7 IOCTLs with no access checks and a zero security descriptor on the device object, meaning any user (including low-integrity processes) can open a handle. Primitives include arbitrary physical memory read via MmMapIoSpace (up to 2MB per call), arbitrary MSR read/write (including IA32_LSTAR for instant kernel code execution), arbitrary I/O port read/write, and arbitrary PCI configuration space read/write. A full LSTAR hijack PoC with crash-safe ROP restore has been demonstrated. The developer acknowledged the issue and is working on a rewritten driver.

UUID / b3f7c8d2-4a19-4e5b-9d6c-2f8e1a3b7c04ADDED / 2026-04-06AUTHOR / Michael Haag

Known samples 1

1 recorded TRUE · 0 recorded FALSE · 0 unknown for loading despite HVCI. Results apply to individual samples.

DriversCloud_amd64.sysSample 1 · HVCI TRUE
MD5
49d1002443655bc63b8d49fef0b584fd
SHA1
6397f7a838b541614a03379787033be9285053cb
SHA256
2bc72d11fa0beda25dc1dbc372967db49bd3c3a3903913f0877bff6792724dfe
Imphash
609a0efe14b66b1a341d1856df00b9fa
Authentihash MD5
75eb4c5b4810d7255c86e67134d63b22
Authentihash SHA1
b4f6bd67bbd4f89809959f40bd6066a101d080b6
Authentihash SHA256
52dd5cb7c2ed6c3b9416811fa9a26fe7a20e25c8ed8c950130c532b30c431dec
Machine
AMD64
Version
10.0.0.0
Publisher
CybelSoft

Recorded command

sc.exe create DriversCloud_amd64 binPath=C:\windows\temp\DriversCloud_amd64.sys type=kernel && sc.exe start DriversCloud_amd64

Elevate privileges · Privileges: kernel · OS: Windows 10

Research & references

Acknowledgement: weezerOSINT @weezerOSINT