← Back to driver explorer
Driver intelligenceVulnerableVerified

stdcdrv64.sys

The Carbon Black Threat Analysis Unit (TAU) discovered 34 unique vulnerable drivers (237 file hashes) accepting firmware access. Six allow kernel memory access. All give full control of the devices to non-admin users. By exploiting the vulnerable drivers, an attacker without the system privilege may erase/alter firmware, and/or elevate privileges. As of the time of writing in October 2023, the filenames of the vulnerable drivers have not been made public until now.

UUID / f33c2e80-7b01-416b-821a-ed06db4b6511ADDED / 2023-11-02AUTHOR / Takahiro Haruyama

Known samples 1

0 recorded TRUE · 1 recorded FALSE · 0 unknown for loading despite HVCI. Results apply to individual samples.

stdcdrv64.sysSample 1 · HVCI FALSE
MD5
d95c9a241e52b4f967fa4cdb7b99fc80
SHA1
8ea50d7d13ff2d1306fed30a2d136dd6245eb3bc
SHA256
37022838c4327e2a5805e8479330d8ff6f8cd3495079905e867811906c98ea20
Imphash
2e7d3b001306473cbff3d0dc11a6fcbc
Authentihash MD5
e70d9f1ab58cf19930dc7744a9135bd3
Authentihash SHA1
04dd836ca6b4fdc52aeef349d042e629b74f34d0
Authentihash SHA256
59cbdc9190000b1de3719dbdb5d90459c602487672a3bae9c56d8ffae5e64250
Machine
AMD64
Version
2.0.0.0
Publisher
Intel Corporation

Recorded command

sc.exe create stdcdrv64sys binPath= C:\windows\temp\stdcdrv64sys.sys type=kernel && sc.exe start stdcdrv64sys

Elevate privileges · Privileges: kernel · OS: Windows 10

Research & references