DriversCloud_amd64.sys
CYBELSOFT DriversCloud_amd64.sys exposes 7 IOCTLs with no access checks and a zero security descriptor on the device object, meaning any user (including low-integrity processes) can open a handle. Primitives include arbitrary physical memory read via MmMapIoSpace (up to 2MB per call), arbitrary MSR read/write (including IA32_LSTAR for instant kernel code execution), arbitrary I/O port read/write, and arbitrary PCI configuration space read/write. A full LSTAR hijack PoC with crash-safe ROP restore has been demonstrated. The developer acknowledged the issue and is working on a rewritten driver.
Known samples 1
1 recorded TRUE · 0 recorded FALSE · 0 unknown for loading despite HVCI. Results apply to individual samples.
DriversCloud_amd64.sysSample 1 · HVCI TRUE
- MD5
49d1002443655bc63b8d49fef0b584fd- SHA1
6397f7a838b541614a03379787033be9285053cb- SHA256
2bc72d11fa0beda25dc1dbc372967db49bd3c3a3903913f0877bff6792724dfe- Imphash
609a0efe14b66b1a341d1856df00b9fa- Authentihash MD5
75eb4c5b4810d7255c86e67134d63b22- Authentihash SHA1
b4f6bd67bbd4f89809959f40bd6066a101d080b6- Authentihash SHA256
52dd5cb7c2ed6c3b9416811fa9a26fe7a20e25c8ed8c950130c532b30c431dec- Machine
- AMD64
- Version
- 10.0.0.0
- Publisher
- CybelSoft
Recorded command
sc.exe create DriversCloud_amd64 binPath=C:\windows\temp\DriversCloud_amd64.sys type=kernel && sc.exe start DriversCloud_amd64Elevate privileges · Privileges: kernel · OS: Windows 10
Research & references
Acknowledgement: weezerOSINT @weezerOSINT

