pskmad.sys
Panda Security's pskmad.sys 1.1.0.23 exposes a memory-read interface protected by a caller-supplied named-event and shared-section authentication exchange. An administrator-controlled process can satisfy that exchange and use the accepted handle to read memory through IOCTL 0xB3702C08. Static analysis of this exact sample confirms a path that copies from valid kernel virtual addresses into the IOCTL output. The device grants access to administrators and LocalSystem; this is not a standard-user entry point. This record tracks the newly reported authentication weakness, not the older Panda CVEs, and does not establish affected versions beyond this exact sample.
Known samples 1
0 recorded TRUE · 0 recorded FALSE · 1 unknown for loading despite HVCI. Results apply to individual samples.
pskmad.sysSample 1 · HVCI unknown
- MD5
43fe428d3e109c81bb1737afd0f9bfa6- SHA1
7be590049b5396056f2384a3b56bf2db11b286e1- SHA256
9bf3b737afa4d4f5e7b00ec749d4b75656ad66d9a2b402e1e81934e95ba7df5b- Imphash
7170ec91f64a93d0b46d51b933b99cca- Authentihash MD5
32053f9201fb51142637e36bb0f63c99- Authentihash SHA1
611678a21e02e30ac5baeeb9bcaf2fe12a91900e- Authentihash SHA256
5fdb1e7e324f6a5537d63e92f5d8ee7d92891f36171665fbd2d1e73e3db1935f- Machine
- AMD64
- Version
- 1.1.0.23
- Publisher
- Panda Security, S.L.U.
Research & references
Acknowledgement: Xusheng Li @xusheng6

