← Back to driver explorer
Driver intelligenceVulnerableVerified

TVicPort64.sys

Load TVicPort64.sys kernel driver. Once loaded, device \\.\TVicPortDevice0 is accessible from any integrity level (no DACL). Send IOCTL 0x80002008 to map arbitrary physical memory into user-mode VA space via ZwMapViewOfSection and perform token stealing for LPE to SYSTEM.

UUID / b4f3a1c2-e8d7-4f92-a301-5c6d9e0b1a2fADDED / 2026-02-13AUTHOR / Joao Leko Monteiro

Known samples 1

0 recorded TRUE · 0 recorded FALSE · 1 unknown for loading despite HVCI. Results apply to individual samples.

TVicPort64.sysSample 1 · HVCI unknown
MD5
A65643ED30A30E46317C0B25818BC9B7
SHA1
3740F2BC7E81D75604E47A3119FAA887D4A92A44
SHA256
9C9AB56C8BCF5EC958E7C2346F23A3027F69ABDF8AF923B591518EEE64AD98AD
Authentihash MD5
A65643ED30A30E46317C0B25818BC9B7
Authentihash SHA1
3740F2BC7E81D75604E47A3119FAA887D4A92A44
Authentihash SHA256
9C9AB56C8BCF5EC958E7C2346F23A3027F69ABDF8AF923B591518EEE64AD98AD
Machine
AMD64
Version
5, 2, 1, 0
Publisher
EnTech Taiwan
View on VirusTotal

Recorded command

sc.exe create TVicPort64 binPath=C:\windows\temp\TVicPort64.sys type=kernel && sc.exe start TVicPort64

Arbitrary physical memory read/write from user mode. Exploitable from Low Integrity Level, Guest, or any AppContainer. Used for local privilege escalation to NT AUTHORITY\SYSTEM via token stealing, KASLR bypass, and kernel code execution. · Privileges: User (Low Integrity sufficient — no DACL on device object) · OS: Windows 10, Windows 11

Research & references

Acknowledgement: Joao Leko Monteiro @lleekkoo-0xdeadbeeftimestwo