b4f3a1c2-e8d7-4f92-a301-5c6d9e0b1a2f
TVicPort64.sys 
Description
Load TVicPort64.sys kernel driver. Once loaded, device \.\TVicPortDevice0 is accessible from any integrity level (no DACL). Send IOCTL 0x80002008 to map arbitrary physical memory into user-mode VA space via ZwMapViewOfSection and perform token stealing for LPE to SYSTEM.
- UUID: b4f3a1c2-e8d7-4f92-a301-5c6d9e0b1a2f
- Created: 2026-02-13
- Author: Joao Leko Monteiro
- Acknowledgement: Joao Leko Monteiro | @lleekkoo-0xdeadbeeftimestwo
This download link contains the vulnerable driver!
Commands
sc.exe create TVicPort64 binPath=C:\windows\temp\TVicPort64.sys type=kernel && sc.exe start TVicPort64
| Use Case | Privileges | Operating System |
|---|---|---|
| Arbitrary physical memory read/write from user mode. Exploitable from Low Integrity Level, Guest, or any AppContainer. Used for local privilege escalation to NT AUTHORITY\SYSTEM via token stealing, KASLR bypass, and kernel code execution. | User (Low Integrity sufficient — no DACL on device object) | Windows 10, Windows 11 |
Detections
YARA 🏹
Expand
with header and size limitation
without header and size limitation
for renamed driver files
Resources
CVE
Known Vulnerable Samples
| Property | Value |
|---|---|
| Filename | TVicPort64.sys |
| Creation Timestamp | |
| MD5 | A65643ED30A30E46317C0B25818BC9B7 |
| SHA1 | 3740F2BC7E81D75604E47A3119FAA887D4A92A44 |
| SHA256 | 9C9AB56C8BCF5EC958E7C2346F23A3027F69ABDF8AF923B591518EEE64AD98AD |
| Authentihash MD5 | A65643ED30A30E46317C0B25818BC9B7 |
| Authentihash SHA1 | 3740F2BC7E81D75604E47A3119FAA887D4A92A44 |
| Authentihash SHA256 | 9C9AB56C8BCF5EC958E7C2346F23A3027F69ABDF8AF923B591518EEE64AD98AD |
| Publisher | EnTech Taiwan |
| Date | 10:20 AM 10/13/2006 |
| Company | EnTech Taiwan |
| Description | TVicPort Generic Device Driver for direct hardware I/O |
| Product | TVicPort |
| OriginalFilename | TVicPort64.sys |
Imports
Expand
- ntoskrnl.exe
- hal.dll
Imported Functions
Expand
Exported Functions
Expand
- D
- r
- i
- v
- e
- r
- E
- n
- t
- r
- y
Sections
Expand
Signature
Expand
last_updated: 2026-04-06
