← Back to driver explorer
Driver intelligenceVulnerableVerified

stdcdrvws64.sys

The Carbon Black Threat Analysis Unit (TAU) discovered 34 unique vulnerable drivers (237 file hashes) accepting firmware access. Six allow kernel memory access. All give full control of the devices to non-admin users. By exploiting the vulnerable drivers, an attacker without the system privilege may erase/alter firmware, and/or elevate privileges. As of the time of writing in October 2023, the filenames of the vulnerable drivers have not been made public until now.

UUID / dc3fdbd3-601a-4d2a-bf34-d2e84c6ff1d3ADDED / 2023-11-02AUTHOR / Takahiro Haruyama

Known samples 1

0 recorded TRUE · 1 recorded FALSE · 0 unknown for loading despite HVCI. Results apply to individual samples.

stdcdrvws64.sysSample 1 · HVCI FALSE
MD5
003dc41d148ec3286dc7df404ba3f2aa
SHA1
948fa3149742f73bf3089893407df1b20f78a563
SHA256
70afdc0e11db840d5367afe53c35d9642c1cf616c7832ab283781d085988e505
Imphash
67affe6126c1d4a774b2504061c96a2e
Authentihash MD5
fc47e6d80dc89fc8ac7d7a85a677f801
Authentihash SHA1
68ea69d26c24877d531b180ffb81b2f6dfdc2b0b
Authentihash SHA256
53f2bfe03b5d74c9db8c6a849e5a4690cba9a9861dd98c204865000506d8ce67
Machine
AMD64
Version
1.0.1.0 built by: WinDDK
Publisher
Intel Corp.

Recorded command

sc.exe create stdcdrvws64sys binPath= C:\windows\temp\stdcdrvws64sys.sys type=kernel && sc.exe start stdcdrvws64sys

Elevate privileges · Privileges: kernel · OS: Windows 10

Research & references