TVicPort64.sys
Load TVicPort64.sys kernel driver. Once loaded, device \\.\TVicPortDevice0 is accessible from any integrity level (no DACL). Send IOCTL 0x80002008 to map arbitrary physical memory into user-mode VA space via ZwMapViewOfSection and perform token stealing for LPE to SYSTEM.
Known samples 1
0 recorded TRUE · 0 recorded FALSE · 1 unknown for loading despite HVCI. Results apply to individual samples.
TVicPort64.sysSample 1 · HVCI unknown
- MD5
A65643ED30A30E46317C0B25818BC9B7- SHA1
3740F2BC7E81D75604E47A3119FAA887D4A92A44- SHA256
9C9AB56C8BCF5EC958E7C2346F23A3027F69ABDF8AF923B591518EEE64AD98AD- Authentihash MD5
A65643ED30A30E46317C0B25818BC9B7- Authentihash SHA1
3740F2BC7E81D75604E47A3119FAA887D4A92A44- Authentihash SHA256
9C9AB56C8BCF5EC958E7C2346F23A3027F69ABDF8AF923B591518EEE64AD98AD- Machine
- AMD64
- Version
- 5, 2, 1, 0
- Publisher
- EnTech Taiwan
Recorded command
sc.exe create TVicPort64 binPath=C:\windows\temp\TVicPort64.sys type=kernel && sc.exe start TVicPort64Arbitrary physical memory read/write from user mode. Exploitable from Low Integrity Level, Guest, or any AppContainer. Used for local privilege escalation to NT AUTHORITY\SYSTEM via token stealing, KASLR bypass, and kernel code execution. · Privileges: User (Low Integrity sufficient — no DACL on device object) · OS: Windows 10, Windows 11
Research & references
Acknowledgement: Joao Leko Monteiro @lleekkoo-0xdeadbeeftimestwo

