← Back to driver explorer
Driver intelligenceVulnerableVerified
BS_RCIO64.sys
BIOSTAR BS_RCIO64_W10 exposes IOCTLs 0x226004 and 0x226008 that map caller-selected physical addresses with MmMapIoSpace and read from or write to the mapped range. Additional IOCTLs expose raw port and PCI configuration access, providing privileged hardware-control primitives suitable for kernel tampering.
Known samples 2
0 recorded TRUE · 2 recorded FALSE · 0 unknown for loading despite HVCI. Results apply to individual samples.
BS_RCIO64.sysSample 1 · HVCI FALSE
- MD5
b10b210c5944965d0dc85e70a0b19a42- SHA1
5db61d00a001fd493591dc919f69b14713889fc5- SHA256
d205286bffdf09bc033c09e95c519c1c267b40c2ee8bab703c6a2d86741ccd3e- Imphash
095c0cdb9c0421da216371c1f4e8790e- Authentihash MD5
380a4fd97d795fec244add19a9c21fd6- Authentihash SHA1
6832acd68bcf08f8ced63023b5f7da36824cc596- Authentihash SHA256
6991be9952aa08c0d2ac9fa728410ebdb44988b496ed01b8b7f478785ebb30c4- Machine
- AMD64
- Version
- 10.0.1901.1100
- Publisher
- BIOSTAR Group
BS_RCIO64_W10.sysSample 2 · HVCI FALSE
- MD5
83f77a67e70733496fde17a1792fa33b- SHA1
9ffb0e96d1354b04533c70af6c8cd2cbfa5e5db3- SHA256
7c6f16af074c3f1c74fc69734f1c8b8a03b0594ac2085d5a0c582fc8cc378858- Imphash
095c0cdb9c0421da216371c1f4e8790e- Authentihash MD5
327031c34a1a13c823de2a708f8ebb52- Authentihash SHA1
c52a0178c9705949a6ec200543ea500e1bcf4f9b- Authentihash SHA256
41e0ceb69b3725bb0f8ae5ed94d81cd19e3775785e8f6f42523cb13250569baa- Machine
- AMD64
- Version
- 10, 0, 1806, 2200
- Publisher
- BIOSTAR Group
Recorded command
sc.exe create BS_RCIO64.sys binPath=C:\windows\temp\BS_RCIO64.sys type=kernel && sc.exe start BS_RCIO64.sysElevate privileges · Privileges: kernel · OS: Windows 10
Research & references
- https://github.com/jbaines-r7/dellicious
- https://www.rapid7.com/blog/post/2021/12/13/driver-based-attacks-past-and-present/
- https://github.com/elastic/protections-artifacts/blob/932baf346cc8a743f1963ad3d4565b42ed17bebe/yara/rules/Windows_VulnDriver_Biostar.yar#L54
- https://nephosec.com/cve-biostar-exploit/
- https://github.com/fluffycats31/vulnerable-drivers
Acknowledgement: fluffycats31 @fluffycats31

