← Back to driver explorer
Driver intelligenceVulnerableVerified
stdcdrv64.sys
The Carbon Black Threat Analysis Unit (TAU) discovered 34 unique vulnerable drivers (237 file hashes) accepting firmware access. Six allow kernel memory access. All give full control of the devices to non-admin users. By exploiting the vulnerable drivers, an attacker without the system privilege may erase/alter firmware, and/or elevate privileges. As of the time of writing in October 2023, the filenames of the vulnerable drivers have not been made public until now.
Known samples 1
0 recorded TRUE · 1 recorded FALSE · 0 unknown for loading despite HVCI. Results apply to individual samples.
stdcdrv64.sysSample 1 · HVCI FALSE
- MD5
d95c9a241e52b4f967fa4cdb7b99fc80- SHA1
8ea50d7d13ff2d1306fed30a2d136dd6245eb3bc- SHA256
37022838c4327e2a5805e8479330d8ff6f8cd3495079905e867811906c98ea20- Imphash
2e7d3b001306473cbff3d0dc11a6fcbc- Authentihash MD5
e70d9f1ab58cf19930dc7744a9135bd3- Authentihash SHA1
04dd836ca6b4fdc52aeef349d042e629b74f34d0- Authentihash SHA256
59cbdc9190000b1de3719dbdb5d90459c602487672a3bae9c56d8ffae5e64250- Machine
- AMD64
- Version
- 2.0.0.0
- Publisher
- Intel Corporation
Recorded command
sc.exe create stdcdrv64sys binPath= C:\windows\temp\stdcdrv64sys.sys type=kernel && sc.exe start stdcdrv64sysElevate privileges · Privileges: kernel · OS: Windows 10

