<?xml version="1.0" encoding="utf-8"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>LOLDrivers</title><link>https://www.loldrivers.io/</link><description>Vulnerable and malicious Windows drivers</description><atom:link href="https://www.loldrivers.io/index.xml" rel="self" type="application/rss+xml"/><item><title>ampg.sys</title><link>https://www.loldrivers.io/drivers/bd5bc879-6602-4338-938e-0873f71bd3d0/</link><guid>https://www.loldrivers.io/drivers/bd5bc879-6602-4338-938e-0873f71bd3d0/</guid><pubDate>Tue, 08 Sep 2026 00:00:00 GMT</pubDate><description>Nextron Systems identifies this exact sample as a rootkit combining network interception, obfuscated file operations, and security-product targeting. Observed and embedded filename metadata identify it as ampg.sys. Static analysis confirms WFP filtering and packet-injection paths, XOR-based file transformation, and a process-termination routine explicitly invoked for 360Tray.exe and ZhuDongFangYu.exe. Its embedded version fields claim Microsoft Corporation and SD Crashdump Port Driver; these are file metadata claims, not evidence of Microsoft authorship. No runtime test of successful security-product termination was performed.</description></item><item><title>MemLoaderCustomize.sys</title><link>https://www.loldrivers.io/drivers/e69e3427-97cd-43bb-aeda-f1fbbeaa75f6/</link><guid>https://www.loldrivers.io/drivers/e69e3427-97cd-43bb-aeda-f1fbbeaa75f6/</guid><pubDate>Tue, 08 Sep 2026 00:00:00 GMT</pubDate><description>Nextron Systems identifies these samples as MemLoaderCustomize kernel PE-loader variants. Capabilities reported across the pair include kernel hooking, module hiding, and deletion; module hiding is specifically attributed to the c6825f94 sample. Static analysis confirms matching loader implementations that allocate image memory, copy PE sections, apply relocations, resolve kernel imports, and prepare mapped-image execution, together with file-deletion helpers. Both contain a MemLoaderCustomize.pdb build path. Module hiding and successful runtime self-deletion remain source-reported rather than dynamically tested.</description></item><item><title>PlugPlayService.sys</title><link>https://www.loldrivers.io/drivers/03d1a3a2-e76c-4fd5-a134-55ec983fdc4c/</link><guid>https://www.loldrivers.io/drivers/03d1a3a2-e76c-4fd5-a134-55ec983fdc4c/</guid><pubDate>Tue, 08 Sep 2026 00:00:00 GMT</pubDate><description>Nextron Systems identified PlugPlayService.sys as a heavily obfuscated, WHQL-signed malicious Windows kernel driver providing arbitrary memory access and direct access to RAID devices. Nextron catalogs this exact sample as an obfuscated kernel PE loader with arbitrary shellcode execution capabilities. Its embedded signature uses Microsoft Windows Hardware Compatibility Publisher. Nextron reports control-flow obfuscation similarities to RegPhantom and reports that xigmapper has deployed similar drivers; these observations do not establish that this exact sample is RegPhantom or was deployed by a particular xigmapper sample. Static analysis confirms encoded indirect calls, system-thread creation, physical-memory mapping, and enumeration of Disk driver device objects. The neonddu.sys sample has byte-identical PE sections and the same Authentihash as PlugPlayService.sys, but has a different embedded signature that fails cryptographic verification; the WHQL signing observation applies to PlugPlayService.sys, not neonddu.sys.</description></item><item><title>rksafe.sys</title><link>https://www.loldrivers.io/drivers/5cbb1918-f7ac-4de8-b334-0bb4824a516b/</link><guid>https://www.loldrivers.io/drivers/5cbb1918-f7ac-4de8-b334-0bb4824a516b/</guid><pubDate>Tue, 08 Sep 2026 00:00:00 GMT</pubDate><description>Nextron Systems identifies this rksafe sample as a rootkit with input interception, anti-debugging, minifilter callbacks, and process protection. Static analysis confirms cross-process memory read/write routines, minifilter registration with a communication port, process and thread object callbacks, and logic that clears KdDebuggerEnabled. Input interception and successful runtime protection effects were not independently tested.</description></item><item><title>RzDev_00X10.sys</title><link>https://www.loldrivers.io/drivers/adf27819-c7a0-4476-8632-5ca759202542/</link><guid>https://www.loldrivers.io/drivers/adf27819-c7a0-4476-8632-5ca759202542/</guid><pubDate>Tue, 08 Sep 2026 00:00:00 GMT</pubDate><description>Nextron Systems identifies this exact sample as a kernel communication and memory-access component with a covert user-to-kernel channel and privileged memory read/write. Static analysis confirms MDL-backed kernel mappings and a transfer path that probes a caller buffer and maps supplied virtual ranges in page-sized chunks. The obfuscated transfer callback was not fully resolved; the covert channel and privileged memory read/write semantics are source-reported, not independently demonstrated. The observed RzDev_00X10.sys filename does not establish vendor ownership.</description></item><item><title>AsusSAIO.sys</title><link>https://www.loldrivers.io/drivers/207b30f5-e3da-4eb2-829f-54b946eb526a/</link><guid>https://www.loldrivers.io/drivers/207b30f5-e3da-4eb2-829f-54b946eb526a/</guid><pubDate>Mon, 31 Aug 2026 00:00:00 GMT</pubDate><description>ASUS System Analysis IO release lines before 1.0.30.0 and before 3.1.41.0 are affected by CVE-2024-55408. The tracked 1.0.1.0 through 1.0.9.0 builds fall inside the affected 1.x line and expose FILE_ANY_ACCESS platform-control IOCTLs through the \Device\AsusSAIO interface. Capabilities vary by build and include PCI-derived MMIO, SMBus, I/O-port, and model-specific register operations without a caller-token authorization gate, allowing local callers to misuse privileged hardware controls.</description></item><item><title>atidsmxx.sys</title><link>https://www.loldrivers.io/drivers/347d5d79-35e6-4438-885f-57a7c95eeb89/</link><guid>https://www.loldrivers.io/drivers/347d5d79-35e6-4438-885f-57a7c95eeb89/</guid><pubDate>Mon, 31 Aug 2026 00:00:00 GMT</pubDate><description>AMD&apos;s ATI DSM Dynamic Driver exposes hardware-control IOCTLs through \Device\AtiDCM. The interface accepts caller-controlled MSR indexes for RDMSR operations and exposes PCI/device I/O and physical-address mapping paths. These privileged primitives can disclose hardware state and support kernel-level tampering when the device is accessible from user mode.</description></item><item><title>BSMEM64_W10.sys</title><link>https://www.loldrivers.io/drivers/685c38ea-6939-4b02-a250-b47dcfecf817/</link><guid>https://www.loldrivers.io/drivers/685c38ea-6939-4b02-a250-b47dcfecf817/</guid><pubDate>Mon, 31 Aug 2026 00:00:00 GMT</pubDate><description>Biostar BSMEM64_W10 exposes direct physical-memory and port/PCI access through \Device\BSMEM. IOCTLs 0x226044 and 0x226084 map caller-selected physical addresses with MmMapIoSpace and copy data from or to the mapped region, providing arbitrary physical-memory read and write primitives.</description></item><item><title>fbiosdrv.sys</title><link>https://www.loldrivers.io/drivers/dc82ae79-d3e2-439a-a4c7-ec1f23e1261b/</link><guid>https://www.loldrivers.io/drivers/dc82ae79-d3e2-439a-a4c7-ec1f23e1261b/</guid><pubDate>Mon, 31 Aug 2026 00:00:00 GMT</pubDate><description>Fujitsu BIOS Driver versions before 2.5.0.0 are affected by CVE-2025-65001. The tracked 1.2.1.0 through 2.4.0.0 fBiosDrv.sys builds all precede the fixed release. A crafted request from a local authenticated administrator can trigger an out-of-bounds write, potentially causing arbitrary kernel code execution or denial of service.</description></item><item><title>fekern.sys</title><link>https://www.loldrivers.io/drivers/8858c9c8-e570-41ed-a5cc-054d9eb51d40/</link><guid>https://www.loldrivers.io/drivers/8858c9c8-e570-41ed-a5cc-054d9eb51d40/</guid><pubDate>Mon, 31 Aug 2026 00:00:00 GMT</pubDate><description>Trellix HX Agent fekern.sys 34.x is affected by CVE-2025-14963. The signed FireEye 34.5.0 and 34.8.0 builds tracked here expose the \\Device\\fekern_00 interface. Used as a standalone BYOVD, the vulnerable driver can provide access to LSASS memory and enable local privilege escalation. A fully functioning HX Agent restricts access through tamper protection.</description></item><item><title>hax.sys</title><link>https://www.loldrivers.io/drivers/9771266b-72e2-4ed3-ac14-1ac25dc5fb25/</link><guid>https://www.loldrivers.io/drivers/9771266b-72e2-4ed3-ac14-1ac25dc5fb25/</guid><pubDate>Mon, 31 Aug 2026 00:00:00 GMT</pubDate><description>Intel Hardware Accelerated Execution Manager versions before 7.7.1 are affected by CVE-2022-21812. The tracked 6.1.0 through 7.7.0 IntelHaxm.sys builds all precede the fixed release. Improper access control on the \Device\GHAX interface allows an authenticated local user to cross the user-to-kernel security boundary and elevate privileges.</description></item><item><title>PGPwded.sys</title><link>https://www.loldrivers.io/drivers/1a0fab94-f4a7-48c2-a2f4-72d19c382642/</link><guid>https://www.loldrivers.io/drivers/1a0fab94-f4a7-48c2-a2f4-72d19c382642/</guid><pubDate>Mon, 31 Aug 2026 00:00:00 GMT</pubDate><description>PGPwded.sys and eedDiskEncryptionDriver.sys are Symantec drive-encryption filters affected by CVE-2019-9702 and CVE-2019-9703. Symantec Endpoint Encryption releases before 11.3.0 and all Symantec Encryption Desktop releases are affected. The tracked filters expose raw-sector read and write controls. In the 11.1.1 eedDiskEncryptionDriver build, any-access IOCTLs 0x8002206C and 0x80022070 select a tracked volume and read or write sectors; its protected-range logic still permits writes beginning in sectors 0 through 2, leaving boot-sector modification possible.</description></item><item><title>pskmad_64.sys</title><link>https://www.loldrivers.io/drivers/c67ad48b-223e-40f8-bfc7-0cb904d0a3d7/</link><guid>https://www.loldrivers.io/drivers/c67ad48b-223e-40f8-bfc7-0cb904d0a3d7/</guid><pubDate>Mon, 31 Aug 2026 00:00:00 GMT</pubDate><description>Panda Kernel Memory Access Driver versions through 1.1.0.21 are affected by CVE-2023-6330, CVE-2023-6331, and CVE-2023-6332. The tracked 1.0.0.16 and 1.0.0.17 builds expose IOCTL 0xB3702C08 through \Device\PSMEMDriver. After a fixed magic value, the request accepts a process, address, and caller-controlled length without relating that length to the fixed buffered-I/O header, allowing kernel-memory disclosure and buffered-output corruption.</description></item><item><title>snxpsamd.sys</title><link>https://www.loldrivers.io/drivers/300cdb55-6e01-4365-83e5-5783be2f9262/</link><guid>https://www.loldrivers.io/drivers/300cdb55-6e01-4365-83e5-5783be2f9262/</guid><pubDate>Mon, 31 Aug 2026 00:00:00 GMT</pubDate><description>SUNIX Serial Driver x64 version 10.1.0.0 is affected by CVE-2024-55412. This exact signed build exposes raw I/O-port operations to low-privilege callers through IOCTLs including 0x9C403C04 and 0x9C403C08. An attacker can use the unrestricted port read/write primitives to disclose information, tamper with privileged hardware state, and elevate privileges.</description></item><item><title>WibuKey64.sys</title><link>https://www.loldrivers.io/drivers/a07e5897-3835-4188-9e3e-bd810c3e34a5/</link><guid>https://www.loldrivers.io/drivers/a07e5897-3835-4188-9e3e-bd810c3e34a5/</guid><pubDate>Mon, 31 Aug 2026 00:00:00 GMT</pubDate><description>WibuKey for Windows releases before 6.70 are affected by CVE-2024-45181 and CVE-2024-45182. Version 6.70 is separately affected by the boundary-validation flaw documented in WIBU-100057 and fixed in 6.71. The tracked 6.40 and 6.50a builds fall in the first affected range. In the tracked 6.70 build, subcommand 0x14 of IOCTL 0x8200E804 combines a caller-controlled offset with an input-buffer pointer without validating that the resulting object remains inside the request, enabling out-of-bounds kernel access.</description></item><item><title>windrvr1251.sys</title><link>https://www.loldrivers.io/drivers/d2a619bb-c8c6-4c79-8b6a-8368668bbfb2/</link><guid>https://www.loldrivers.io/drivers/d2a619bb-c8c6-4c79-8b6a-8368668bbfb2/</guid><pubDate>Mon, 31 Aug 2026 00:00:00 GMT</pubDate><description>Jungo WinDriver versions 6.0.0 through 16.1.0 are affected by multiple kernel security issues fixed in version 16.2.0. The tracked 12.5.1 through 14.1.1 builds fall inside that affected interval. CVE-2024-26314 allows a low-privileged local attacker to escalate privileges and execute arbitrary code. The 14.1.1 driver exposes METHOD_NEITHER requests that reach port I/O, PCI configuration, and mapped-resource operations after the required WinDriver registration workflow.</description></item><item><title>d39DuiY9sxtDSiu4LSvS.sys</title><link>https://www.loldrivers.io/drivers/3207f14b-a66c-4d5e-a5d5-2467ffd58265/</link><guid>https://www.loldrivers.io/drivers/3207f14b-a66c-4d5e-a5d5-2467ffd58265/</guid><pubDate>Sat, 29 Aug 2026 00:00:00 GMT</pubDate><description>This purpose-built kernel loader creates the \\.\wifis device and accepts encrypted PE images through IOCTL 0x222000. Its worker thread decrypts input with an RC4-like routine using the embedded key dsmjklsafbv, manually maps the supplied PE image, resolves imports and relocations, and transfers execution to the unsigned payload in kernel memory.</description></item><item><title>giveio.sys</title><link>https://www.loldrivers.io/drivers/50bbae3f-f6d8-4881-8fd7-a70002d52841/</link><guid>https://www.loldrivers.io/drivers/50bbae3f-f6d8-4881-8fd7-a70002d52841/</guid><pubDate>Sat, 29 Aug 2026 00:00:00 GMT</pubDate><description>The 32-bit giveio driver bundled with SpeedFan creates the \\.\giveio device and handles IRP_MJ_CREATE by applying a zeroed 8 KiB I/O permission map to the opening process through Ke386IoSetAccessProcess and Ke386SetIoAccessMap. This grants unrestricted direct access to all x86 I/O ports without validating the caller.</description></item><item><title>HP_SWTOOLS_DRIVER.sys</title><link>https://www.loldrivers.io/drivers/19f13965-7078-4c19-a2e3-71ab8b77a9b7/</link><guid>https://www.loldrivers.io/drivers/19f13965-7078-4c19-a2e3-71ab8b77a9b7/</guid><pubDate>Sat, 29 Aug 2026 00:00:00 GMT</pubDate><description>HP_SWTOOLS_DRIVER exposes privileged CPU and memory operations through the \\.\HP_WKS_SWTOOLS_DRIVER device. Static analysis confirms IOCTLs for MSR read and write, performance-counter access, physical/MMIO mapping and read/write, PCI configuration access, port I/O, and a CPU-halt path. A standard user can reach the device after an administrator installs the driver.</description></item><item><title>PSKD64.SYS</title><link>https://www.loldrivers.io/drivers/7789e9ca-8508-486b-9d77-7497c5c61474/</link><guid>https://www.loldrivers.io/drivers/7789e9ca-8508-486b-9d77-7497c5c61474/</guid><pubDate>Sat, 29 Aug 2026 00:00:00 GMT</pubDate><description>APSoft PCIScope&apos;s PSKD64 driver exposes memory-access operations through \\.\PSKD64. IOCTL 0x220044 dispatches sub-operations 0x701E and 0x701F for caller-selected virtual or physical memory reads and writes without constraining the target address. Public testing demonstrates arbitrary kernel read/write on Windows 11, including process protection removal and security-process termination.</description></item><item><title>kernel_utility_driver64.sys</title><link>https://www.loldrivers.io/drivers/c7f94129-f95f-4848-b1ab-68aae24275e7/</link><guid>https://www.loldrivers.io/drivers/c7f94129-f95f-4848-b1ab-68aae24275e7/</guid><pubDate>Fri, 28 Aug 2026 00:00:00 GMT</pubDate><description>Huorong Security identified these WHCP-signed kernel drivers in Vaultify rogueware. After a challenge-response exchange, the driver accepts a target driver name and removes process-creation callbacks registered by that driver. This strips callback-based antivirus and EDR visibility from kernel context. Public analysis reproduced the behavior in both the 32-bit and 64-bit builds.</description></item><item><title>sxav64-v1.5.1.sys</title><link>https://www.loldrivers.io/drivers/b1f406cd-117a-45bb-97db-3f9ecb44f70d/</link><guid>https://www.loldrivers.io/drivers/b1f406cd-117a-45bb-97db-3f9ecb44f70d/</guid><pubDate>Fri, 28 Aug 2026 00:00:00 GMT</pubDate><description>The signed SXClient sxav.sys security driver processes an SXBOOTDB boot configuration whose integrity is protected only by an unkeyed MD5 digest. Public research demonstrates that an administrator can generate a valid configuration containing arbitrary absolute paths, point the service to it, and have the kernel driver delete those files during the next boot. The primitive can be abused to remove security-product files that are otherwise locked while Windows is running.</description></item><item><title>xhunter2.sys</title><link>https://www.loldrivers.io/drivers/ed3abb66-c577-44b8-89fa-80d300c82373/</link><guid>https://www.loldrivers.io/drivers/ed3abb66-c577-44b8-89fa-80d300c82373/</guid><pubDate>Fri, 28 Aug 2026 00:00:00 GMT</pubDate><description>Wellbia xhunter2.sys version 2026.6.1.192 is an XIGNCODE3 anti-cheat kernel component affected by CVE-2026-15430. Public research demonstrates bypasses for its module, caller, and request authentication layers, exposing privileged command paths for cross-process memory access, protected-process handle creation, process termination, local privilege escalation, and kernel-assisted code injection.</description></item><item><title>Alinubx.sys</title><link>https://www.loldrivers.io/drivers/84a3007a-de5e-4622-bfc5-f05d927c3618/</link><guid>https://www.loldrivers.io/drivers/84a3007a-de5e-4622-bfc5-f05d927c3618/</guid><pubDate>Thu, 27 Aug 2026 00:00:00 GMT</pubDate><description>Alinubx.sys exposes IOCTL 0x222024 which allows user-mode applications to terminate arbitrary processes from the kernel via ZwTerminateProcess. The IOCTL input buffer expects a structure containing the PID (DWORD) and an exit status code (DWORD). Abused by the Cruciferra MaaS loader to kill AV/EDR processes.</description></item><item><title>DCRCVDrv.sys</title><link>https://www.loldrivers.io/drivers/89643454-e38b-41cb-853d-abf649a104a5/</link><guid>https://www.loldrivers.io/drivers/89643454-e38b-41cb-853d-abf649a104a5/</guid><pubDate>Thu, 27 Aug 2026 00:00:00 GMT</pubDate><description>DCRCVDrv.sys exposes IOCTL 0x2205C0 which allows user-mode applications to terminate arbitrary processes from the kernel via ZwTerminateProcess. The IOCTL input buffer contains the PID to terminate. Abused by the Cruciferra MaaS loader, which writes the driver to C:\Windows\Temp\DCRCVDrv.sys, creates a service for it, and opens a handle via the symbolic link \\.\DCRCVDRV_U to kill AV/EDR processes.</description></item><item><title>KKYUM.sys</title><link>https://www.loldrivers.io/drivers/459c39a0-d6bd-4d3e-91ae-a701bb0b3198/</link><guid>https://www.loldrivers.io/drivers/459c39a0-d6bd-4d3e-91ae-a701bb0b3198/</guid><pubDate>Wed, 12 Aug 2026 00:00:00 GMT</pubDate><description>The driver creates a device object named &quot;\\.\KKYUM&quot; without strict access controls, allowing low-privileged users to interact with it. It exposes unauthenticated IOCTL control codes &quot;0x22265C&quot; (Read) and &quot;0x222658&quot; (Write) that encapsulate the MmCopyVirtualMemory kernel API. The handler accepts a target Process ID (PID) and a structured array of source/destination virtual addresses directly from user space without checking execution privileges, enabling local attackers to perform unauthorized arbitrary process memory reads and writes against any active process.</description></item><item><title>zntport.sys</title><link>https://www.loldrivers.io/drivers/8fcec30c-f5ca-4aae-b2d8-77af60b78d42/</link><guid>https://www.loldrivers.io/drivers/8fcec30c-f5ca-4aae-b2d8-77af60b78d42/</guid><pubDate>Tue, 11 Aug 2026 00:00:00 GMT</pubDate><description>The legacy NTPort driver creates the &quot;\\.\zntport&quot; device and exposes IOCTL 0xF10024CC with FILE_ANY_ACCESS. The handler accepts a caller-controlled 32-bit physical address, maps 0x32 bytes below 4 GiB with MmMapIoSpace, and copies data through an unchecked strcpy operation. After an administrator installs the driver, an unprivileged process may be able to abuse the device for physical-memory disclosure or memory corruption, depending on the device ACL.</description></item><item><title>ktapi.sys</title><link>https://www.loldrivers.io/drivers/8a6aebaa-34aa-46e8-a864-4189a55fd17b/</link><guid>https://www.loldrivers.io/drivers/8a6aebaa-34aa-46e8-a864-4189a55fd17b/</guid><pubDate>Fri, 10 Jul 2026 00:00:00 GMT</pubDate><description>ktapi.sys is a legacy cross-signed Kontron Technology Application Programming Interface driver that exposes the \\.\ktapi device to user mode. IOCTL 0x82007000 accepts a caller-controlled interface type, bus address, and size before using HalTranslateBusAddress, ZwOpenSection, and ZwMapViewOfSection to map physical memory into the calling process. Certain interface types cause HalTranslateBusAddress to return the supplied address unchanged, allowing an attacker to map arbitrary system RAM for physical-memory read and write. Expel documented this primitive in an EDR-killer exploit used by The Gentlemen ransomware group to obtain kernel code execution and terminate security processes.</description></item><item><title>QIOMem.sys</title><link>https://www.loldrivers.io/drivers/6eca187c-8fb2-4eae-9c80-fd9ef9d8c91e/</link><guid>https://www.loldrivers.io/drivers/6eca187c-8fb2-4eae-9c80-fd9ef9d8c91e/</guid><pubDate>Fri, 10 Jul 2026 00:00:00 GMT</pubDate><description>QIOMem.sys is the Generic IO &amp; Memory Access driver included with Toshiba and Dynabook password utilities. It binds to ACPI\QCI0701; on systems without that firmware device, the public proof of concept creates a matching software PnP device to trigger loading of an already-installed driver package. Six IOCTLs (0x08012000 through 0x08012014) pass an unvalidated 32-bit physical address to MmMapIoSpace, allowing a low-privileged process to read or write one, two, or four bytes of physical memory below 4 GiB.</description></item><item><title>MonProcessEX.sys</title><link>https://www.loldrivers.io/drivers/c3c083d2-e9bd-4891-8582-46086de2b2b4/</link><guid>https://www.loldrivers.io/drivers/c3c083d2-e9bd-4891-8582-46086de2b2b4/</guid><pubDate>Wed, 08 Jul 2026 00:00:00 GMT</pubDate><description>MonProcessEX.sys is a HONOR MagicAnimation and HONOR PCManager kernel driver that exposes IOCTL 0x22400C to reach ZwTerminateProcess. The device is accessible to LocalSystem and local administrators, and the process-termination path does not verify the caller, allowing an administrator-accessible client to terminate arbitrary user-mode processes except PID 0 and PID 4 from kernel mode.</description></item><item><title>pstrip64.sys</title><link>https://www.loldrivers.io/drivers/1db2dd90-5b8e-43c3-a39b-61e0614fb2ab/</link><guid>https://www.loldrivers.io/drivers/1db2dd90-5b8e-43c3-a39b-61e0614fb2ab/</guid><pubDate>Thu, 25 Jun 2026 00:00:00 GMT</pubDate><description>pstrip64.sys is the EnTech Taiwan PowerStrip x64 kernel-mode driver, signed by EnTech Taiwan. In PowerStrip version 3.90.736 and earlier, the driver&apos;s IOCTL dispatcher exposes code 0x80002008, which maps caller-supplied physical memory directly into the requesting user-mode process and returns the mapped virtual base address, giving a local user an arbitrary physical read/write primitive. Public exploitation of CVE-2026-29923 uses this to scan physical memory for the EPROCESS &apos;Proc&apos; pool tag, copy the SYSTEM process token, and overwrite the caller&apos;s token to escalate to NT AUTHORITY\SYSTEM.</description></item><item><title>360netmon_wfp.sys</title><link>https://www.loldrivers.io/drivers/acb5da93-1dcc-4d16-8415-6b4b221cb4a1/</link><guid>https://www.loldrivers.io/drivers/acb5da93-1dcc-4d16-8415-6b4b221cb4a1/</guid><pubDate>Mon, 22 Jun 2026 00:00:00 GMT</pubDate><description>Qihoo 360netmon_wfp.sys is a signed kernel driver documented by ESET as the driver abused by the GentleKiller Network Blocker variant used in Gentlemen ransomware intrusions. The sample is associated with ESET detection Win64/VulnDriver.Qihoo360.A.</description></item><item><title>IMFForceDelete</title><link>https://www.loldrivers.io/drivers/6ca608ec-df2e-4a8d-8a0b-350f9e0271ab/</link><guid>https://www.loldrivers.io/drivers/6ca608ec-df2e-4a8d-8a0b-350f9e0271ab/</guid><pubDate>Mon, 22 Jun 2026 00:00:00 GMT</pubDate><description>IObit Malware Fighter IMFForceDelete.sys is a vulnerable force-delete filter driver. ESET documents GentleKiller&apos;s Cleaner variant dropping this driver without the trailing .sys extension, and CVE-2019-6494 describes IOCTL 0x8016E000 allowing low-privileged users to delete files regardless of access controls.</description></item><item><title>MyPortIO_x64.sys</title><link>https://www.loldrivers.io/drivers/7d9fee48-82d8-4582-be9a-a46682054e3e/</link><guid>https://www.loldrivers.io/drivers/7d9fee48-82d8-4582-be9a-a46682054e3e/</guid><pubDate>Mon, 22 Jun 2026 00:00:00 GMT</pubDate><description>MyPortIO_x64.sys and MyPortIO_x86.sys are Nuvoton Technology kernel drivers bundled with ASRock Polychrome RGB. Public issue #380 and the MyPortIO-Exploit writeup document unauthenticated IOCTL handlers that expose physical memory read/write and I/O port access primitives from user mode.</description></item><item><title>ardrv.sys</title><link>https://www.loldrivers.io/drivers/9eb0156e-4c43-487f-be8c-40a7b19a4279/</link><guid>https://www.loldrivers.io/drivers/9eb0156e-4c43-487f-be8c-40a7b19a4279/</guid><pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate><description>OPSWAT AppRemover ardrv.sys version 2017.10.02.1551 and earlier exposes a user-accessible \\.\ardrv device. Public research documents IOCTL 0x2420031 reaching process-termination paths, including ZwTerminateProcess, without sufficient caller or target validation. This allows local users to terminate arbitrary processes, including security tooling, and makes the driver useful in BYOVD-style defense impairment after it is loaded. Acronis observed the tracked ardrv.sys variant in an August 2026 campaign where it was used to terminate Microsoft Defender, Huorong, and Tencent security processes before SparkRAT deployment.</description></item><item><title>AsrDrv107.sys</title><link>https://www.loldrivers.io/drivers/2d3178da-ea76-4f36-93f4-d76bf846c240/</link><guid>https://www.loldrivers.io/drivers/2d3178da-ea76-4f36-93f4-d76bf846c240/</guid><pubDate>Tue, 16 Jun 2026 00:00:00 GMT</pubDate><description>ASRock AsrDrv107.sys and AsrDrv107n.sys are ASRock IO driver builds listed as KDU providers for ASRock Motherboard Utility versions 3.0.498 and below. The driver family is associated with CVE-2020-15368 and exposes low-level privileged access primitives used by KDU.</description></item><item><title>CcProtect.sys</title><link>https://www.loldrivers.io/drivers/3e3067b0-3d74-46fe-9f57-1ae3a0293958/</link><guid>https://www.loldrivers.io/drivers/3e3067b0-3d74-46fe-9f57-1ae3a0293958/</guid><pubDate>Tue, 16 Jun 2026 00:00:00 GMT</pubDate><description>CnCrypt CcProtect.sys is a signed kernel driver used by BlackSnufkin BYOVD research as a process-killer provider. The public PoC documents this hash as a vulnerable CcProtect driver and notes that HVCI must be disabled to avoid instability.</description></item><item><title>Cndom6.sys</title><link>https://www.loldrivers.io/drivers/2703d3dd-05f0-4ae2-83a2-2ad0939467d0/</link><guid>https://www.loldrivers.io/drivers/2703d3dd-05f0-4ae2-83a2-2ad0939467d0/</guid><pubDate>Tue, 16 Jun 2026 00:00:00 GMT</pubDate><description>Signed malicious drivers reported in Silver Fox activity; rwdriver.sys exposes a rootkit IOCTL primitive, while Cndom6.sys and XiaoH.sys are reported as watchdog/support drivers.</description></item><item><title>EnPortv.sys</title><link>https://www.loldrivers.io/drivers/18935808-e00c-4b75-a7fc-03e409a7570e/</link><guid>https://www.loldrivers.io/drivers/18935808-e00c-4b75-a7fc-03e409a7570e/</guid><pubDate>Tue, 16 Jun 2026 00:00:00 GMT</pubDate><description>Guidance Software EnPortv.sys is an older EnCase kernel driver documented in KOSEC BYOVD research and in public reporting on signed forensic drivers used by EDR-killer tooling. KOSEC documents a KillProc IOCTL path that can terminate a target process when called from an administrator context with the expected caller PID material.</description></item><item><title>GameDriverX64.sys</title><link>https://www.loldrivers.io/drivers/271ace20-2f68-4695-9579-0d4de8cb4fe6/</link><guid>https://www.loldrivers.io/drivers/271ace20-2f68-4695-9579-0d4de8cb4fe6/</guid><pubDate>Tue, 16 Jun 2026 00:00:00 GMT</pubDate><description>GameDriverX64.sys is a signed Hotta Studio anti-cheat driver affected by CVE-2025-61155. Its device-access and IOCTL checks rely on spoofable module names, process names, PE checksums, and the hardcoded value 0xFA123456. A local user can reach kernel routines that terminate arbitrary processes, register a process for handle protection, and strip existing handle rights. KSophon_x64.sys is the VMProtect-packed predecessor shipped with Tower of Fantasy; public reverse engineering reports that it retains the same weak authentication and IOCTL capabilities. The tracked files are legitimate vendor-signed drivers, not malicious drivers, although GameDriverX64.sys has been abused for defense evasion in ransomware intrusions.</description></item><item><title>KExplore.sys</title><link>https://www.loldrivers.io/drivers/1b916d35-f62b-41ef-8454-3aed20299cb0/</link><guid>https://www.loldrivers.io/drivers/1b916d35-f62b-41ef-8454-3aed20299cb0/</guid><pubDate>Tue, 16 Jun 2026 00:00:00 GMT</pubDate><description>KExplore.sys is Pavel Yosifovich&apos;s Kernel Explorer driver and is listed as a KDU-compatible provider. KDU uses supported provider drivers to access kernel memory primitives for actions such as process-object modification and driver mapping.</description></item><item><title>KObjExp.sys</title><link>https://www.loldrivers.io/drivers/8347c4af-8946-4135-b890-cde3ed35fc28/</link><guid>https://www.loldrivers.io/drivers/8347c4af-8946-4135-b890-cde3ed35fc28/</guid><pubDate>Tue, 16 Jun 2026 00:00:00 GMT</pubDate><description>KObjExp.sys is Pavel Yosifovich&apos;s Kernel Object Explorer driver and is listed as a KDU-compatible provider. The staged samples include the KDU provider hash and a separate JobExplorer build of the same driver family.</description></item><item><title>KRegExp.sys</title><link>https://www.loldrivers.io/drivers/eada0015-c868-463c-91a6-d159ee1110d7/</link><guid>https://www.loldrivers.io/drivers/eada0015-c868-463c-91a6-d159ee1110d7/</guid><pubDate>Tue, 16 Jun 2026 00:00:00 GMT</pubDate><description>KRegExp.sys is Pavel Yosifovich&apos;s Kernel Registry Explorer driver and is listed as a KDU-compatible provider. KDU uses provider drivers to perform privileged kernel operations including kernel memory access and process-object manipulation.</description></item><item><title>LECOMAx64.sys</title><link>https://www.loldrivers.io/drivers/47d4b71f-eebd-4775-9e7c-b031135e8f1b/</link><guid>https://www.loldrivers.io/drivers/47d4b71f-eebd-4775-9e7c-b031135e8f1b/</guid><pubDate>Tue, 16 Jun 2026 00:00:00 GMT</pubDate><description>LECOMAx64.sys is a signed LECO LECOMA device driver referenced by public PPLShade supported-driver research.</description></item><item><title>LnvMSRIO.sys</title><link>https://www.loldrivers.io/drivers/87680018-393b-47b6-8130-6b41bed2bc7c/</link><guid>https://www.loldrivers.io/drivers/87680018-393b-47b6-8130-6b41bed2bc7c/</guid><pubDate>Tue, 16 Jun 2026 00:00:00 GMT</pubDate><description>LnvMSRIO.sys is a Lenovo Dispatcher driver affected by CVE-2025-8061. The tracked 3.0.2.28 through 3.1.0.36 builds predate Lenovo&apos;s fixed 3.1.0.41 driver. The WinMsrDev interface exposes physical-memory read and write through IOCTLs 0x9C406104 and 0x9C40A108 and MSR read and write through 0x9C402084 and 0x9C402088, allowing an authenticated local user to execute code with elevated privileges when Memory Integrity is not enabled.</description></item><item><title>NeacSafe64.sys</title><link>https://www.loldrivers.io/drivers/d474d8ad-14d9-4664-addd-86b4a9b7a1a5/</link><guid>https://www.loldrivers.io/drivers/d474d8ad-14d9-4664-addd-86b4a9b7a1a5/</guid><pubDate>Tue, 16 Jun 2026 00:00:00 GMT</pubDate><description>NetEase NeacSafe64.sys is an anti-cheat mini-filter driver referenced by KDU and public NeacController research. Versions prior to 1.0.0.8 expose IOCTL/message-handler paths that provide arbitrary kernel read/write primitives and can be chained for SYSTEM privilege escalation or kernel-mode code execution.</description></item><item><title>pcdsrvc_x64.sys</title><link>https://www.loldrivers.io/drivers/d4eb6ed4-c23f-45a9-9891-5aa8f218b863/</link><guid>https://www.loldrivers.io/drivers/d4eb6ed4-c23f-45a9-9891-5aa8f218b863/</guid><pubDate>Tue, 16 Jun 2026 00:00:00 GMT</pubDate><description>PC-Doctor pcdsrvc_x64.sys is listed as a KDU provider for Dell PC Doctor / SupportAssist driver abuse. The driver family is associated with CVE-2019-12280 and exposes kernel access primitives used by KDU as a provider for kernel memory operations.</description></item><item><title>PCTcore64.sys</title><link>https://www.loldrivers.io/drivers/8f2d3be4-3e25-490f-82bc-0aca16aee101/</link><guid>https://www.loldrivers.io/drivers/8f2d3be4-3e25-490f-82bc-0aca16aee101/</guid><pubDate>Tue, 16 Jun 2026 00:00:00 GMT</pubDate><description>PC Tools PCTcore64.sys is documented by BlackSnufkin BYOVD research and CERT/CC as CVE-2026-8501. The driver creates a PCTCore device interface without restrictive access controls and exposes a process-termination IOCTL reachable by local callers.</description></item><item><title>pmxdrv64.sys</title><link>https://www.loldrivers.io/drivers/95fc9bf0-ec86-44b3-abad-a4c922aa7742/</link><guid>https://www.loldrivers.io/drivers/95fc9bf0-ec86-44b3-abad-a4c922aa7742/</guid><pubDate>Tue, 16 Jun 2026 00:00:00 GMT</pubDate><description>Intel PMxDrv / pmxdrv64.sys is listed as a KDU provider for Intel Management Engine Tools driver abuse. Public vulnerable-driver research also documents physical-memory access through this driver family.</description></item><item><title>RootLaser.sys</title><link>https://www.loldrivers.io/drivers/4c9a91ff-9284-49a7-899d-dfe85a112465/</link><guid>https://www.loldrivers.io/drivers/4c9a91ff-9284-49a7-899d-dfe85a112465/</guid><pubDate>Tue, 16 Jun 2026 00:00:00 GMT</pubDate><description>Adlice RootLaser.sys version 3.4.1 is a signed kernel driver with administrator-reachable kernel read and write primitives through IOCTLs 0x22E050 and 0x22E014. Public proof-of-concept code combines these primitives with build-specific kernel offsets to replace a process token and elevate an administrator to SYSTEM. The exploit requires offsets that match the target Windows build.</description></item><item><title>shield.sys</title><link>https://www.loldrivers.io/drivers/0e272ccf-81e5-4612-95d2-365e7ded6eac/</link><guid>https://www.loldrivers.io/drivers/0e272ccf-81e5-4612-95d2-365e7ded6eac/</guid><pubDate>Tue, 16 Jun 2026 00:00:00 GMT</pubDate><description>Horizon DataSys Shield drivers expose IOCTL functionality reported to provide arbitrary kernel read/write primitives.</description></item><item><title>tdevflt.sys</title><link>https://www.loldrivers.io/drivers/65458077-861e-4423-b446-2a9c7afe44b5/</link><guid>https://www.loldrivers.io/drivers/65458077-861e-4423-b446-2a9c7afe44b5/</guid><pubDate>Tue, 16 Jun 2026 00:00:00 GMT</pubDate><description>This ABYSSWORKER-related malicious kernel driver presents as Palo Alto Networks tdevflt.sys / Cortex XDR PnP Device Filter Driver. Public DragonForce reporting lists the sample in a BYOVD tradecraft set alongside known vulnerable process-killer drivers.</description></item><item><title>unknown.sys</title><link>https://www.loldrivers.io/drivers/bffcac17-f20c-43cc-baf0-93fd20bc1ed5/</link><guid>https://www.loldrivers.io/drivers/bffcac17-f20c-43cc-baf0-93fd20bc1ed5/</guid><pubDate>Tue, 16 Jun 2026 00:00:00 GMT</pubDate><description>unknown.sys is an unattributed signed kernel driver documented in public UnknownKiller / BlackSnufkin BYOVD research. The public PoCs identify the driver as exposing a process-kill primitive suitable for BYOVD process termination research.</description></item><item><title>xhunter1.sys</title><link>https://www.loldrivers.io/drivers/96ba5e53-6a40-4813-b6f1-ccce31a883cf/</link><guid>https://www.loldrivers.io/drivers/96ba5e53-6a40-4813-b6f1-ccce31a883cf/</guid><pubDate>Tue, 16 Jun 2026 00:00:00 GMT</pubDate><description>Wellbia xhunter1.sys is an XIGNCODE3 anti-cheat kernel component affected by CVE-2026-3609 through version 2023.12.7.78. Public research demonstrates that its unauthenticated command channel can expose protected-process handles, read cross-process memory, terminate security processes, elevate privileges, and inject code from kernel context.</description></item><item><title>xkpsm.sys</title><link>https://www.loldrivers.io/drivers/767ed0a0-606b-4297-a858-e2af5b4a0400/</link><guid>https://www.loldrivers.io/drivers/767ed0a0-606b-4297-a858-e2af5b4a0400/</guid><pubDate>Tue, 16 Jun 2026 00:00:00 GMT</pubDate><description>xkpsm.sys is an xkeeper kernel driver from JiranJikyosoft. The driver exposes IOCTL 0x8505E008 to user mode and reaches ZwTerminateProcess, enabling kernel-mediated process termination without sufficient caller or target validation. This makes the driver useful in BYOVD-style process termination and security tool impairment scenarios after it is loaded.</description></item><item><title>ZYArKit.sys</title><link>https://www.loldrivers.io/drivers/f2032ff3-9c67-4d48-981b-2479babb153d/</link><guid>https://www.loldrivers.io/drivers/f2032ff3-9c67-4d48-981b-2479babb153d/</guid><pubDate>Tue, 16 Jun 2026 00:00:00 GMT</pubDate><description>V-secure ZYArKit.sys version 2.0.13.5 is a signed kernel driver assessed in public KOSEC BYOVD research. KOSEC documents an IOCTL path that references a user-supplied process handle and reaches ZwTerminateProcess, allowing administrator-context termination of non-protected processes from kernel mode.</description></item><item><title>ProcessCtr.sys</title><link>https://www.loldrivers.io/drivers/5d658b45-81f0-442e-ac43-7c249ce1d54f/</link><guid>https://www.loldrivers.io/drivers/5d658b45-81f0-442e-ac43-7c249ce1d54f/</guid><pubDate>Tue, 09 Jun 2026 00:00:00 GMT</pubDate><description>EsafeNet ProcessCtr / ProcessCtrl64.sys creates a device object reachable by local callers and exposes process-control IOCTL paths. Public research documents a vulnerable process-termination path that can allow privileged process termination or denial of service when user-supplied context/handle material is accepted without adequate authorization checks.</description></item><item><title>PGRHostControl.sys</title><link>https://www.loldrivers.io/drivers/82eee73e-156e-4344-b975-babbf0bc131f/</link><guid>https://www.loldrivers.io/drivers/82eee73e-156e-4344-b975-babbf0bc131f/</guid><pubDate>Sat, 06 Jun 2026 00:00:00 GMT</pubDate><description>PGRHostControl.sys is a signed kernel driver distributed by FLIR Integrated Imaging Solutions, Inc. (formerly Point Grey Research). The driver exposes multiple privileged IOCTL handlers that can be accessed without sufficient authorization checks, allowing user-controlled requests to map arbitrary physical memory through \Device\PhysicalMemory and provides unrestricted I/O port read and write primitives via the x86 IN/OUT instructions. These capabilities can be abused to access physical RAM, interact directly with hardware registers, access MMIO regions, and potentially facilitate local privilege escalation or post-exploitation activity. Due to the absence of adequate access controls around highly privileged operations, the driver constitutes a Bring Your Own Vulnerable Driver (BYOVD) primitive.</description></item><item><title>NGStar.sys</title><link>https://www.loldrivers.io/drivers/5b9a202c-0695-532e-9d92-662cedefee07/</link><guid>https://www.loldrivers.io/drivers/5b9a202c-0695-532e-9d92-662cedefee07/</guid><pubDate>Mon, 01 Jun 2026 00:00:00 GMT</pubDate><description>NGStar.sys is the kernel-mode USB fingerprint sensor driver for NITGEN Fingkey Hamster II/III devices. The driver creates \Device\gstar-0 exposed as \\.\gstar-0 via IoCreateDevice with FILE_DEVICE_UNKNOWN and no IoCreateDeviceSecure call, making all 28 IOCTL codes (0x00222004-0x00222070) reachable by any unprivileged user-mode process (FILE_ANY_ACCESS on all codes). IOCTLs 0x0022206C and 0x00222070 allocate a fixed 10-byte NonPagedPool block via the deprecated ExAllocatePool API then pass it directly as the receive buffer for an uncapped USB bulk transfer with no post-transfer bounds check — kernel pool overflow leading to local privilege escalation to SYSTEM. ExAllocatePool (non-tagged, removed from Windows 11 and Server 2022 kernel exports) causes a kernel bugcheck (BSOD) on any IOCTL reaching the allocation path — confirmed local DoS. IOCTL 0x00222050 decrements a session reference counter at [rbp+0x40] via lock add without an underflow guard; counter wraps to 0xFFFFFFFF from zero, corrupting the device extension refcount and triggering premature cleanup leading to use-after-free. Driver carries no embedded PE signature; trusted via catalog fdu11.cat (VeriSign-signed, expired 2014, valid via timestamp countersignature). VT detection: 0/77.</description></item><item><title>bootrepair.sys</title><link>https://www.loldrivers.io/drivers/7cc0a40d-7902-4400-9fc4-0070053991cb/</link><guid>https://www.loldrivers.io/drivers/7cc0a40d-7902-4400-9fc4-0070053991cb/</guid><pubDate>Tue, 19 May 2026 00:00:00 GMT</pubDate><description>BootRepair.sys is a legitimate Lenovo kernel driver shipped with Lenovo PC Manager (signed by LENOVO via Symantec Class 3 SHA256 Code Signing CA, compile date 2018-01-03). The driver creates a device object at \\.\BootRepair with no DACL restrictions, so any local user can open a handle. The IRP_MJ_DEVICE_CONTROL dispatcher accepts IOCTL 0x222014 with a 4-byte DWORD input (target PID) and chains PsLookupProcessByProcessId -&gt; ObOpenObjectByPointer -&gt; ZwTerminateProcess against the supplied PID, with no caller validation. Because the kernel-mode caller bypasses user-mode access checks, the primitive can terminate any process on the system including PPL-protected AV/EDR processes. The driver also imports ZwCreateKey / ZwSetValueKey / ZwQueryValueKey (registry access for the boot-repair feature), PsCreateSystemThread / IoRegisterShutdownNotification, and KeBugCheckEx.</description></item><item><title>deresute64.sys</title><link>https://www.loldrivers.io/drivers/dbd78de7-f5ab-4fb7-a246-39cbcca4678c/</link><guid>https://www.loldrivers.io/drivers/dbd78de7-f5ab-4fb7-a246-39cbcca4678c/</guid><pubDate>Tue, 05 May 2026 00:00:00 GMT</pubDate><description>Create and start driver</description></item><item><title>Driver_win10.sys</title><link>https://www.loldrivers.io/drivers/cb9f4425-66de-4371-a3df-3aeec1fda65c/</link><guid>https://www.loldrivers.io/drivers/cb9f4425-66de-4371-a3df-3aeec1fda65c/</guid><pubDate>Tue, 05 May 2026 00:00:00 GMT</pubDate><description>Kernel driver family observed dropped by Black Basta tooling and adjacent intrusions during 2025. The 55 KB sample is signed by Microsoft Windows Hardware Compatibility Publisher (WHQL attestation), allowing it to load on systems with HVCI enabled. Two additional 44 KB unsigned variants share the same imphash and identical/near-identical authentihashes, indicating the same driver body redistributed without the embedded signature blob. Imports include FltEnumerateFilters and FltUnregisterFilter (minifilter enumeration and unregistration), MmCopyVirtualMemory (cross-process kernel-assisted memory copy), ZwTerminateProcess and ZwOpenProcess (process termination), and KeStackAttachProcess (process attach) — primitives suitable for tamper protection or evasion of endpoint security minifilters.</description></item><item><title>qu829.sys</title><link>https://www.loldrivers.io/drivers/3599f0ef-67fc-4130-910f-0c482612d16f/</link><guid>https://www.loldrivers.io/drivers/3599f0ef-67fc-4130-910f-0c482612d16f/</guid><pubDate>Tue, 05 May 2026 00:00:00 GMT</pubDate><description>Kernel driver signed by &quot;Fuqing Yuntan Network Tech Co.,Ltd.&quot; (a revoked VeriSign code-signing certificate that Microsoft has flagged as abused). Multiple samples in this family produce a Cobalt Strike beacon reflective loader YARA hit (Elastic protections-artifacts ruleset Windows_Trojan_CobaltStrike) and are detected by Microsoft as Trojan:Win32/Hitbrovi.G. Samples are dropped to C:\Windows under random eight-character filenames (e.g. qu829.exe) and registered as kernel services. Both observed variants share imphash ca73883db8881686fb258a9d289e3909.</description></item><item><title>360hvm64.sys</title><link>https://www.loldrivers.io/drivers/d4d82af5-0ac6-4d5d-944f-cf108475aba9/</link><guid>https://www.loldrivers.io/drivers/d4d82af5-0ac6-4d5d-944f-cf108475aba9/</guid><pubDate>Thu, 30 Apr 2026 00:00:00 GMT</pubDate><description>360hvm64.sys is the kernel-mode hypervisor enforcement driver shipped with Qihoo 360 Total Security. IOCTL 0x22240c on \\.\360Hvm issues a per-CPU DPC broadcast that executes VMXOFF/VMSKINIT on every logical processor, disabling VT-x/AMD-V hypervisor protection across all CPUs; the auth gate (sub_121f4) delegates to \Device\360SelfProtection and fails open when that companion device is absent (BYOVD scenario).</description></item><item><title>AppShopDrv103.sys</title><link>https://www.loldrivers.io/drivers/29d2c408-c1c6-451a-acf6-eddd59969183/</link><guid>https://www.loldrivers.io/drivers/29d2c408-c1c6-451a-acf6-eddd59969183/</guid><pubDate>Wed, 22 Apr 2026 00:00:00 GMT</pubDate><description>AppShopDrv103.sys is a hardware utility driver from ASRock distributed with APP Shop and Auto Driver Installer. The driver exposes 30+ IOCTLs through a BCrypt AES-encrypted command wrapper (IOCTL 0x22EC00) with a hardcoded key, providing arbitrary physical memory read and write via MmMapIoSpace (IOCTLs 0x22E808/0x22E80C), unrestricted I/O port read and write in byte, word, and dword widths (IOCTLs 0x22E810-0x22E824), full PCI configuration space read and write via port 0xCF8/0xCFC (IOCTLs 0x22E830-0x22E844), MSR read and write via rdmsr/wrmsr (IOCTLs 0x22E848/0x22E84C), control register reads for CR0/CR2/CR3/CR4/CR8 (IOCTL 0x22E86C), RDTSC and RDPMC performance counter access, CPUID execution, and contiguous memory allocation. Same vulnerability class as other ASRock drivers (AsrDrv.sys) already tracked in LOLDrivers. Used by KDU (Kernel Driver Utility) as a provider.</description></item><item><title>BdApiUtil.sys</title><link>https://www.loldrivers.io/drivers/83b78b88-3b43-41cc-a60f-cab1a7b96978/</link><guid>https://www.loldrivers.io/drivers/83b78b88-3b43-41cc-a60f-cab1a7b96978/</guid><pubDate>Wed, 22 Apr 2026 00:00:00 GMT</pubDate><description>BdApiUtil.sys is a kernel driver from Baidu Antivirus that exposes dangerous primitives to usermode with no authentication. The driver provides process termination by PID via PsLookupProcessByProcessId and ZwTerminateProcess (IOCTL 0x800024B4), process suspension via dynamically-resolved NtSuspendProcess (IOCTL 0x800024B8), full kernel registry CRUD including ZwOpenKey (0x80002190), ZwCreateKey (0x80002194), ZwSetValueKey (0x80002198), ZwDeleteKey (0x8000219C), and ZwDeleteValueKey (0x800021A0), and kernel-mode file creation via ObInsertObject/ZwCreateFile (0x80002324). The process termination primitive is exploited by the GoodBaiii EDR killer tool. Registry callback monitoring via CmRegisterCallback and process creation monitoring via PsSetCreateProcessNotifyRoutine are also present.</description></item><item><title>devhost.sys</title><link>https://www.loldrivers.io/drivers/d0cc79b2-a789-4cf3-9a88-25bdabb79416/</link><guid>https://www.loldrivers.io/drivers/d0cc79b2-a789-4cf3-9a88-25bdabb79416/</guid><pubDate>Wed, 22 Apr 2026 00:00:00 GMT</pubDate><description>devhost.sys is a WHQL attestation-signed kernel driver that exposes arbitrary memory read primitives to usermode. The device object at \\.\devhost has no ACL beyond a device handle. At load, the driver reads IA32_LSTAR MSR to locate ntoskrnl base via backward MZ walk, then dynamically resolves APIs (including MmMapIoSpace and MmCopyMemory) using a djb2-style hash algorithm over the PE export directory. Only 11 benign imports are visible statically. The system CR3 is leaked to user-mode at DriverEntry. Authentication uses a hardcoded magic cookie via IOCTL 0x28E017. IOCTL 0x28E01B accepts a caller-supplied CR3 and target virtual address, performs a manual 4-level x64 page-table walk (PML4-PDPT-PD-PT), and reads physical memory via MmMapIoSpace. Additional IOCTLs expose NtBuildNumber, PsLoadedModuleList, and per-CPU KPCR CurrentThread. Nextron Research noted that these primitives are tailor-made for credential theft (e.g. LSASS memory dumping), though no confirmed malicious usage has been publicly documented. WHQL attestation signed with active cert (Nov 2025-Nov 2026). SpcSpOpusInfo identifies the submitter as Shenzhen Aolian Information Security Technology Co Ltd.</description></item><item><title>GoFly64.sys</title><link>https://www.loldrivers.io/drivers/c2ed6a76-95ad-45fd-97d4-b55deefb3e32/</link><guid>https://www.loldrivers.io/drivers/c2ed6a76-95ad-45fd-97d4-b55deefb3e32/</guid><pubDate>Wed, 22 Apr 2026 00:00:00 GMT</pubDate><description>GoFly64.sys is a WFP (Windows Filtering Platform) network filter driver signed by a Chinese software company (南京偲言睿网络科技有限公司 / Nanjing Siyanrui Network Technology) that exposes 20+ IOCTLs to usermode with no authentication. The most critical primitive is IOCTL 0x12227A which opens any process by PID via ZwOpenProcess and terminates it via ZwTerminateProcess, enabling kernel-level EDR/AV process killing. Additional capabilities include WFP-based network traffic interception and packet injection (FwpsInjectNetworkSendAsync, FwpsInjectNetworkReceiveAsync), IPv4 traffic redirection (IOCTL 0x122262 via RtlIpv4StringToAddressA), process creation monitoring (PsSetCreateProcessNotifyRoutineEx), image load monitoring (PsSetLoadImageNotifyRoutine), and kernel-mode file write operations. VT shows 88 malicious execution parents including malware droppers and PowerShell scripts, confirming heavy abuse in the wild for BYOVD attacks. Also distributed as PandaSpeed64.sys and drv_02581.sys.</description></item><item><title>WinIo64.sys</title><link>https://www.loldrivers.io/drivers/96501e5b-e4f2-41a9-a8ee-d09e36d31a39/</link><guid>https://www.loldrivers.io/drivers/96501e5b-e4f2-41a9-a8ee-d09e36d31a39/</guid><pubDate>Wed, 22 Apr 2026 00:00:00 GMT</pubDate><description>WinIo64 is a hardware-access driver based on the WinIo library that provides direct physical-memory mapping and I/O-port operations from user mode. Its IOCTL interface exposes physical-memory map and unmap, I/O-port read and write, and physical-address translation primitives that are repeatedly incorporated into BYOVD tooling.</description></item><item><title>_xyzxbqvb.rdu_GFAC_Sys_x64.sys</title><link>https://www.loldrivers.io/drivers/63535f5c-9535-4bb0-ae8c-4366d40055f9/</link><guid>https://www.loldrivers.io/drivers/63535f5c-9535-4bb0-ae8c-4366d40055f9/</guid><pubDate>Fri, 17 Apr 2026 00:00:00 GMT</pubDate><description>_xyzxbqvb.rdu_GFAC_Sys_x64.sys is a vulnerable kernel driver from the KeServiceDescriptorTable/vulnerable-drivers repository. The driver exposes dangerous kernel primitives to usermode.</description></item><item><title>1109.sys</title><link>https://www.loldrivers.io/drivers/1adc79ba-d923-4e25-9175-77fa18e10cad/</link><guid>https://www.loldrivers.io/drivers/1adc79ba-d923-4e25-9175-77fa18e10cad/</guid><pubDate>Fri, 17 Apr 2026 00:00:00 GMT</pubDate><description>1109.sys is a vulnerable kernel driver from the KeServiceDescriptorTable/vulnerable-drivers repository. The driver exposes dangerous kernel primitives to usermode.</description></item><item><title>6c8a.sys</title><link>https://www.loldrivers.io/drivers/54af50e5-c964-485a-9b15-d5411971a425/</link><guid>https://www.loldrivers.io/drivers/54af50e5-c964-485a-9b15-d5411971a425/</guid><pubDate>Fri, 17 Apr 2026 00:00:00 GMT</pubDate><description>6c8a.sys is a vulnerable kernel driver from the KeServiceDescriptorTable/vulnerable-drivers repository. The driver exposes dangerous kernel primitives to usermode.</description></item><item><title>AIDA64Driver.sys</title><link>https://www.loldrivers.io/drivers/deffeb8d-c7d9-46b9-a921-7d8d096460ef/</link><guid>https://www.loldrivers.io/drivers/deffeb8d-c7d9-46b9-a921-7d8d096460ef/</guid><pubDate>Fri, 17 Apr 2026 00:00:00 GMT</pubDate><description>AIDA64Driver.sys is a vulnerable kernel driver from the KeServiceDescriptorTable/vulnerable-drivers repository. The driver exposes dangerous kernel primitives to usermode.</description></item><item><title>Amd_RPMC_BiosToolCommonDriver.sys</title><link>https://www.loldrivers.io/drivers/8dbd8d1c-aa4a-418c-9bbe-0730d37d9bb5/</link><guid>https://www.loldrivers.io/drivers/8dbd8d1c-aa4a-418c-9bbe-0730d37d9bb5/</guid><pubDate>Fri, 17 Apr 2026 00:00:00 GMT</pubDate><description>Amd_RPMC_BiosToolCommonDriver.sys is a vulnerable kernel driver from the KeServiceDescriptorTable/vulnerable-drivers repository. The driver exposes dangerous kernel primitives to usermode.</description></item><item><title>AppVkgr.sys</title><link>https://www.loldrivers.io/drivers/fbd12dbb-434e-4950-887a-382b681e8a5a/</link><guid>https://www.loldrivers.io/drivers/fbd12dbb-434e-4950-887a-382b681e8a5a/</guid><pubDate>Fri, 17 Apr 2026 00:00:00 GMT</pubDate><description>AppVkgr.sys is a vulnerable kernel driver from the KeServiceDescriptorTable/vulnerable-drivers repository. The driver exposes dangerous kernel primitives to usermode.</description></item><item><title>AsrCDDrv.sys</title><link>https://www.loldrivers.io/drivers/bd06e043-0f69-4212-be93-d069bf0de848/</link><guid>https://www.loldrivers.io/drivers/bd06e043-0f69-4212-be93-d069bf0de848/</guid><pubDate>Fri, 17 Apr 2026 00:00:00 GMT</pubDate><description>AsrCDDrv.sys is a kernel driver from ASRock Incorporation that exposes control register read/write (cr0, cr2, cr3, cr4, cr8), arbitrary MSR read/write, arbitrary physical memory read/write via MmMapIoSpace, contiguous memory allocation/free via MmAllocateContiguousMemorySpecifyCache, and I/O port read/write (8/16/32-bit). The driver is available in the KeServiceDescriptorTable/vulnerable-drivers repository.</description></item><item><title>bin_intigua_driver64.sys</title><link>https://www.loldrivers.io/drivers/68810b7a-06c5-498a-bbdf-28fb4d5d9201/</link><guid>https://www.loldrivers.io/drivers/68810b7a-06c5-498a-bbdf-28fb4d5d9201/</guid><pubDate>Fri, 17 Apr 2026 00:00:00 GMT</pubDate><description>bin_intigua_driver64.sys is a vulnerable kernel driver from the KeServiceDescriptorTable/vulnerable-drivers repository. The driver exposes dangerous kernel primitives to usermode.</description></item><item><title>BiosToolCommonDriver.sys</title><link>https://www.loldrivers.io/drivers/2d301a46-ceb6-477c-8a51-463a6ded3524/</link><guid>https://www.loldrivers.io/drivers/2d301a46-ceb6-477c-8a51-463a6ded3524/</guid><pubDate>Fri, 17 Apr 2026 00:00:00 GMT</pubDate><description>BiosToolCommonDriver.sys is an AMD RPMC (Replay Protected Monotonic Counter) field fusing utility driver that exposes 18 IOCTLs including arbitrary physical memory read/write via MmMapIoSpace, unrestricted port I/O, PCI configuration space read/write, MSR read/write (wrmsr/rdmsr), SPI flash read, CPUID execution, virtual-to-physical address translation via MmGetPhysicalAddress, and contiguous memory allocation. WHQL Microsoft-signed and also AMD Sectigo dual-signed. Ships inside Razer Blade 16 BIOS update packages and ASUS firmware config bundles. PDB path confirms AMD internal build origin.</description></item><item><title>BS_RVSIO64.sys</title><link>https://www.loldrivers.io/drivers/5281b4b4-1b96-4261-8a1f-5fa22ba44d53/</link><guid>https://www.loldrivers.io/drivers/5281b4b4-1b96-4261-8a1f-5fa22ba44d53/</guid><pubDate>Fri, 17 Apr 2026 00:00:00 GMT</pubDate><description>BS_RVSIO64.sys is a vulnerable kernel driver from the KeServiceDescriptorTable/vulnerable-drivers repository. The driver exposes dangerous kernel primitives to usermode.</description></item><item><title>bsitf.sys</title><link>https://www.loldrivers.io/drivers/9905c737-83ad-4801-a573-8267f3aea924/</link><guid>https://www.loldrivers.io/drivers/9905c737-83ad-4801-a573-8267f3aea924/</guid><pubDate>Fri, 17 Apr 2026 00:00:00 GMT</pubDate><description>bsitf.sys and AsusBSItf.sys are ASUS BIOS Flash Driver naming variants distributed with the ASUS WinFlash utility. The 3.2.12.0 AsusBSItf.sys build exposes physical-memory reads through MmMapIoSpace (IOCTL 0x222804), contiguous kernel-memory allocation mapped to user mode through an MDL (IOCTL 0x222808), arbitrary I/O-port writes and reads (IOCTLs 0x222810 and 0x222818), and PCI configuration-space reads with BAR mapping (IOCTL 0x222814). Public research identifies this low-privilege interface as CVE-2024-33221 and demonstrates its use for privilege escalation, kernel code execution, or information disclosure. Earlier bsitf.sys builds tracked in this record additionally expose BIOS flash writes through IOCTL 0x22281C.</description></item><item><title>chinese_cheat_driver.sys</title><link>https://www.loldrivers.io/drivers/98b064c4-c9ff-4cac-a6b6-a24964b70923/</link><guid>https://www.loldrivers.io/drivers/98b064c4-c9ff-4cac-a6b6-a24964b70923/</guid><pubDate>Fri, 17 Apr 2026 00:00:00 GMT</pubDate><description>chinese_cheat_driver.sys is a vulnerable kernel driver from the KeServiceDescriptorTable/vulnerable-drivers repository. The driver exposes dangerous kernel primitives to usermode. Public exploit research documents IOCTL 0x222000 for arbitrary kernel virtual memory reads, IOCTL 0x222018 for physical memory reads, and IOCTL 0x22201C for physical memory writes, which can be chained for local privilege escalation from an administrator context to NT AUTHORITY\SYSTEM.</description></item><item><title>CmUpx.sys</title><link>https://www.loldrivers.io/drivers/64601d77-61ea-43b7-8178-9d45dfba6022/</link><guid>https://www.loldrivers.io/drivers/64601d77-61ea-43b7-8178-9d45dfba6022/</guid><pubDate>Fri, 17 Apr 2026 00:00:00 GMT</pubDate><description>CmUpx.sys is a vulnerable kernel driver from the KeServiceDescriptorTable/vulnerable-drivers repository. The driver exposes dangerous kernel primitives to usermode.</description></item><item><title>ControlCenter.sys</title><link>https://www.loldrivers.io/drivers/b6873d69-affe-431b-9ba8-459391386603/</link><guid>https://www.loldrivers.io/drivers/b6873d69-affe-431b-9ba8-459391386603/</guid><pubDate>Fri, 17 Apr 2026 00:00:00 GMT</pubDate><description>ControlCenter.sys is a vulnerable kernel driver from the KeServiceDescriptorTable/vulnerable-drivers repository. The driver exposes dangerous kernel primitives to usermode.</description></item><item><title>d591004.sys</title><link>https://www.loldrivers.io/drivers/c22dd43e-cf1f-4338-a109-d662198ffbe9/</link><guid>https://www.loldrivers.io/drivers/c22dd43e-cf1f-4338-a109-d662198ffbe9/</guid><pubDate>Fri, 17 Apr 2026 00:00:00 GMT</pubDate><description>d591004.sys is a vulnerable kernel driver from the KeServiceDescriptorTable/vulnerable-drivers repository. The driver exposes dangerous kernel primitives to usermode.</description></item><item><title>DDDriver.sys</title><link>https://www.loldrivers.io/drivers/6f6aedb9-aeaf-4c13-9d6d-37f062728c38/</link><guid>https://www.loldrivers.io/drivers/6f6aedb9-aeaf-4c13-9d6d-37f062728c38/</guid><pubDate>Fri, 17 Apr 2026 00:00:00 GMT</pubDate><description>DDDriver.sys is a vulnerable kernel driver from the KeServiceDescriptorTable/vulnerable-drivers repository. The driver exposes dangerous kernel primitives to usermode.</description></item><item><title>dddriver64Dcsa.sys</title><link>https://www.loldrivers.io/drivers/705330b3-5e2c-4c87-ab92-0f01b68b1b2d/</link><guid>https://www.loldrivers.io/drivers/705330b3-5e2c-4c87-ab92-0f01b68b1b2d/</guid><pubDate>Fri, 17 Apr 2026 00:00:00 GMT</pubDate><description>dddriver64Dcsa.sys is a vulnerable kernel driver from the KeServiceDescriptorTable/vulnerable-drivers repository. The driver exposes dangerous kernel primitives to usermode.</description></item><item><title>devMemDrv.sys</title><link>https://www.loldrivers.io/drivers/f375e53d-db7c-4149-beff-c8b9329f6f9b/</link><guid>https://www.loldrivers.io/drivers/f375e53d-db7c-4149-beff-c8b9329f6f9b/</guid><pubDate>Fri, 17 Apr 2026 00:00:00 GMT</pubDate><description>devMemDrv.sys is a vulnerable kernel driver from the KeServiceDescriptorTable/vulnerable-drivers repository. The driver exposes dangerous kernel primitives to usermode.</description></item><item><title>ditpio64.sys</title><link>https://www.loldrivers.io/drivers/843a028a-e998-42cb-874c-4478680af397/</link><guid>https://www.loldrivers.io/drivers/843a028a-e998-42cb-874c-4478680af397/</guid><pubDate>Fri, 17 Apr 2026 00:00:00 GMT</pubDate><description>ditpio64.sys is a vulnerable kernel driver from the KeServiceDescriptorTable/vulnerable-drivers repository. The driver exposes dangerous kernel primitives to usermode.</description></item><item><title>DNDrv.sys</title><link>https://www.loldrivers.io/drivers/4e7563f0-0d77-43e9-b765-a509ba121818/</link><guid>https://www.loldrivers.io/drivers/4e7563f0-0d77-43e9-b765-a509ba121818/</guid><pubDate>Fri, 17 Apr 2026 00:00:00 GMT</pubDate><description>DNDrv.sys is a vulnerable kernel driver from the KeServiceDescriptorTable/vulnerable-drivers repository. The driver exposes dangerous kernel primitives to usermode.</description></item><item><title>dXIw8eZ9aYxQYzgm.sys</title><link>https://www.loldrivers.io/drivers/847e6aa7-ce2d-4f4a-aa6c-a00c5f0ad728/</link><guid>https://www.loldrivers.io/drivers/847e6aa7-ce2d-4f4a-aa6c-a00c5f0ad728/</guid><pubDate>Fri, 17 Apr 2026 00:00:00 GMT</pubDate><description>dXIw8eZ9aYxQYzgm.sys is a vulnerable kernel driver from the KeServiceDescriptorTable/vulnerable-drivers repository. The driver exposes dangerous kernel primitives to usermode.</description></item><item><title>energydriver.sys</title><link>https://www.loldrivers.io/drivers/3dc0b91e-6afe-4938-ad9a-2cdf10c2c1e6/</link><guid>https://www.loldrivers.io/drivers/3dc0b91e-6afe-4938-ad9a-2cdf10c2c1e6/</guid><pubDate>Fri, 17 Apr 2026 00:00:00 GMT</pubDate><description>EnergyDriver.sys is a kernel driver from Intel Corporation shipped with Intel Power Gadget 3.6 (deprecated December 2023). The driver exposes 5 IOCTLs including arbitrary wrmsr (any MSR index, any 64-bit value, no whitelist), arbitrary rdmsr (single CPU or all CPUs), and arbitrary physical memory read via MmMapIoSpace. wrmsr allows IA32_LSTAR hijack for direct syscall redirection. No privilege check, no MSR whitelist, default DACL. WHQL and Intel EV dual-signed.</description></item><item><title>evga_kernel_driver-x64.sys</title><link>https://www.loldrivers.io/drivers/02bbc006-a4a4-438f-9b6c-4382303f6b45/</link><guid>https://www.loldrivers.io/drivers/02bbc006-a4a4-438f-9b6c-4382303f6b45/</guid><pubDate>Fri, 17 Apr 2026 00:00:00 GMT</pubDate><description>evga_kernel_driver-x64.sys is a vulnerable kernel driver from the KeServiceDescriptorTable/vulnerable-drivers repository. The driver exposes dangerous kernel primitives to usermode.</description></item><item><title>fastdumpx64.sys</title><link>https://www.loldrivers.io/drivers/619953be-2115-4da2-bb59-603fcf93a3d2/</link><guid>https://www.loldrivers.io/drivers/619953be-2115-4da2-bb59-603fcf93a3d2/</guid><pubDate>Fri, 17 Apr 2026 00:00:00 GMT</pubDate><description>fastdumpx64.sys is a vulnerable kernel driver from the KeServiceDescriptorTable/vulnerable-drivers repository. The driver exposes dangerous kernel primitives to usermode.</description></item><item><title>FDMCJHJYXZITI.sys</title><link>https://www.loldrivers.io/drivers/f650dfc3-d3a1-4a9a-8b71-c599d1f9579c/</link><guid>https://www.loldrivers.io/drivers/f650dfc3-d3a1-4a9a-8b71-c599d1f9579c/</guid><pubDate>Fri, 17 Apr 2026 00:00:00 GMT</pubDate><description>FDMCJHJYXZITI.sys is a vulnerable kernel driver from the KeServiceDescriptorTable/vulnerable-drivers repository. The driver exposes dangerous kernel primitives to usermode.</description></item><item><title>fjfwupgd.sys</title><link>https://www.loldrivers.io/drivers/2e47cd6a-30a2-4790-9f9c-9de7b0d7bf60/</link><guid>https://www.loldrivers.io/drivers/2e47cd6a-30a2-4790-9f9c-9de7b0d7bf60/</guid><pubDate>Fri, 17 Apr 2026 00:00:00 GMT</pubDate><description>fjfwupgd.sys is a vulnerable kernel driver from the KeServiceDescriptorTable/vulnerable-drivers repository. The driver exposes dangerous kernel primitives to usermode.</description></item><item><title>FoxKeDriver64.sys</title><link>https://www.loldrivers.io/drivers/7f52f435-d217-4c13-98a4-4fdc6c8516c8/</link><guid>https://www.loldrivers.io/drivers/7f52f435-d217-4c13-98a4-4fdc6c8516c8/</guid><pubDate>Fri, 17 Apr 2026 00:00:00 GMT</pubDate><description>FoxKeDriver64.sys is a vulnerable Foxconn kernel driver that exposes a \\.\Fox_FOXONE_Driver device. Public research documents IOCTL 0x2220C0 for translating a caller-supplied virtual address to a physical address, which can support local privilege escalation chains with other vulnerable drivers.</description></item><item><title>GGProtect64.sys</title><link>https://www.loldrivers.io/drivers/13d67487-8c65-47bb-a3d3-d799b5f7533b/</link><guid>https://www.loldrivers.io/drivers/13d67487-8c65-47bb-a3d3-d799b5f7533b/</guid><pubDate>Fri, 17 Apr 2026 00:00:00 GMT</pubDate><description>GGProtect64.sys is a Microsoft-signed anticheat kernel driver for GG租号 that exposes a \\.\GGProtect64 device. Public research documents a bypassable caller-registration flow through IOCTL 0x223C14 and a privileged process termination path through IOCTL 0x223C04, allowing a local process to terminate or suspend protected processes from kernel mode.</description></item><item><title>gibepext.sys</title><link>https://www.loldrivers.io/drivers/1e69f91e-4ec5-4c6a-b4a4-2279808b6545/</link><guid>https://www.loldrivers.io/drivers/1e69f91e-4ec5-4c6a-b4a4-2279808b6545/</guid><pubDate>Fri, 17 Apr 2026 00:00:00 GMT</pubDate><description>gibepext.sys is a vulnerable kernel driver from the KeServiceDescriptorTable/vulnerable-drivers repository. The driver exposes dangerous kernel primitives to usermode.</description></item><item><title>GlobalVistaVentures_v3.sys</title><link>https://www.loldrivers.io/drivers/90df671c-a903-49bd-ac62-c124d4f6901d/</link><guid>https://www.loldrivers.io/drivers/90df671c-a903-49bd-ac62-c124d4f6901d/</guid><pubDate>Fri, 17 Apr 2026 00:00:00 GMT</pubDate><description>GlobalVistaVentures_v3.sys is a vulnerable kernel driver from the KeServiceDescriptorTable/vulnerable-drivers repository. The driver exposes dangerous kernel primitives to usermode.</description></item><item><title>HardwareMon-x86.sys</title><link>https://www.loldrivers.io/drivers/24d8bef2-379c-4a27-bd2d-4f13136f3476/</link><guid>https://www.loldrivers.io/drivers/24d8bef2-379c-4a27-bd2d-4f13136f3476/</guid><pubDate>Fri, 17 Apr 2026 00:00:00 GMT</pubDate><description>HardwareMon-x86.sys is a vulnerable kernel driver from the KeServiceDescriptorTable/vulnerable-drivers repository. The driver exposes dangerous kernel primitives to usermode.</description></item><item><title>hp64vision.sys</title><link>https://www.loldrivers.io/drivers/da6709ab-3b7a-445d-9a47-e8b4141d4133/</link><guid>https://www.loldrivers.io/drivers/da6709ab-3b7a-445d-9a47-e8b4141d4133/</guid><pubDate>Fri, 17 Apr 2026 00:00:00 GMT</pubDate><description>hp64vision.sys is a vulnerable kernel driver from the KeServiceDescriptorTable/vulnerable-drivers repository. The driver exposes dangerous kernel primitives to usermode.</description></item><item><title>HWAuidoOs2Ec.sys</title><link>https://www.loldrivers.io/drivers/2c7d54ff-7b49-4da8-ae77-00ac6fa2944f/</link><guid>https://www.loldrivers.io/drivers/2c7d54ff-7b49-4da8-ae77-00ac6fa2944f/</guid><pubDate>Fri, 17 Apr 2026 00:00:00 GMT</pubDate><description>Huawei HWAuidoOs2Ec.sys is a vulnerable kernel driver from public vulnerable-driver research. Public DragonForce reporting also lists this driver in BYOVD tradecraft used to disable endpoint security tooling.</description></item><item><title>ImmunetUtilDriver.sys</title><link>https://www.loldrivers.io/drivers/79e1e3d4-36d0-4325-8d9c-c6e69b6084da/</link><guid>https://www.loldrivers.io/drivers/79e1e3d4-36d0-4325-8d9c-c6e69b6084da/</guid><pubDate>Fri, 17 Apr 2026 00:00:00 GMT</pubDate><description>ImmunetUtilDriver.sys is a vulnerable kernel driver from the KeServiceDescriptorTable/vulnerable-drivers repository. The driver exposes dangerous kernel primitives to usermode.</description></item><item><title>inetcache.sys</title><link>https://www.loldrivers.io/drivers/45b0de20-b3cc-4604-a428-175ea092cd39/</link><guid>https://www.loldrivers.io/drivers/45b0de20-b3cc-4604-a428-175ea092cd39/</guid><pubDate>Fri, 17 Apr 2026 00:00:00 GMT</pubDate><description>inetcache.sys is a vulnerable kernel driver from the KeServiceDescriptorTable/vulnerable-drivers repository. The driver exposes dangerous kernel primitives to usermode.</description></item><item><title>iobios64.sys</title><link>https://www.loldrivers.io/drivers/00755879-eeb3-4a70-9df6-c4e8ff561cdc/</link><guid>https://www.loldrivers.io/drivers/00755879-eeb3-4a70-9df6-c4e8ff561cdc/</guid><pubDate>Fri, 17 Apr 2026 00:00:00 GMT</pubDate><description>iobios64.sys is a vulnerable kernel driver from the KeServiceDescriptorTable/vulnerable-drivers repository. The driver exposes dangerous kernel primitives to usermode.</description></item><item><title>iOCdrv.sys</title><link>https://www.loldrivers.io/drivers/9bf541fb-a68e-41a5-aab2-b939acc22bb1/</link><guid>https://www.loldrivers.io/drivers/9bf541fb-a68e-41a5-aab2-b939acc22bb1/</guid><pubDate>Fri, 17 Apr 2026 00:00:00 GMT</pubDate><description>iOCdrv.sys is a vulnerable kernel driver from the KeServiceDescriptorTable/vulnerable-drivers repository. The driver exposes dangerous kernel primitives to usermode.</description></item><item><title>IoManager.sys</title><link>https://www.loldrivers.io/drivers/2ad22816-46de-45b5-999b-864944635e0a/</link><guid>https://www.loldrivers.io/drivers/2ad22816-46de-45b5-999b-864944635e0a/</guid><pubDate>Fri, 17 Apr 2026 00:00:00 GMT</pubDate><description>IoManager.sys is a vulnerable kernel driver from the KeServiceDescriptorTable/vulnerable-drivers repository. The driver exposes dangerous kernel primitives to usermode.</description></item><item><title>ipctype.sys</title><link>https://www.loldrivers.io/drivers/509edc55-1881-4fac-8640-b9c516396505/</link><guid>https://www.loldrivers.io/drivers/509edc55-1881-4fac-8640-b9c516396505/</guid><pubDate>Fri, 17 Apr 2026 00:00:00 GMT</pubDate><description>ipctype.sys is a kernel driver from Digital Electronics Corporation that exposes physical memory read/write via MmMapIoSpace. The driver is available in the KeServiceDescriptorTable/vulnerable-drivers repository.</description></item><item><title>IUForceDelete.sys</title><link>https://www.loldrivers.io/drivers/b898cc81-1736-45c7-ab41-c104ab17f05d/</link><guid>https://www.loldrivers.io/drivers/b898cc81-1736-45c7-ab41-c104ab17f05d/</guid><pubDate>Fri, 17 Apr 2026 00:00:00 GMT</pubDate><description>IUForceDelete.sys is a vulnerable kernel driver from the KeServiceDescriptorTable/vulnerable-drivers repository. The driver exposes dangerous kernel primitives to usermode.</description></item><item><title>Khwmon.sys</title><link>https://www.loldrivers.io/drivers/b98bc8f5-5dde-417f-a25c-41d95b867d75/</link><guid>https://www.loldrivers.io/drivers/b98bc8f5-5dde-417f-a25c-41d95b867d75/</guid><pubDate>Fri, 17 Apr 2026 00:00:00 GMT</pubDate><description>Khwmon.sys is a vulnerable kernel driver from the KeServiceDescriptorTable/vulnerable-drivers repository. The driver exposes dangerous kernel primitives to usermode.</description></item><item><title>Kinkajou.sys</title><link>https://www.loldrivers.io/drivers/56610446-9914-41f6-a028-33640a683c9d/</link><guid>https://www.loldrivers.io/drivers/56610446-9914-41f6-a028-33640a683c9d/</guid><pubDate>Fri, 17 Apr 2026 00:00:00 GMT</pubDate><description>Kinkajou.sys is a vulnerable kernel driver from the KeServiceDescriptorTable/vulnerable-drivers repository. The driver exposes dangerous kernel primitives to usermode.</description></item><item><title>KmWpsMs.sys</title><link>https://www.loldrivers.io/drivers/a6340f12-b0ee-41c5-acf0-92be886d1296/</link><guid>https://www.loldrivers.io/drivers/a6340f12-b0ee-41c5-acf0-92be886d1296/</guid><pubDate>Fri, 17 Apr 2026 00:00:00 GMT</pubDate><description>KmWpsMs.sys is a vulnerable kernel driver from the KeServiceDescriptorTable/vulnerable-drivers repository. The driver exposes dangerous kernel primitives to usermode.</description></item><item><title>l1malwarebits.sys</title><link>https://www.loldrivers.io/drivers/ec521bd5-8a3f-46ec-b6d3-414b79977a7e/</link><guid>https://www.loldrivers.io/drivers/ec521bd5-8a3f-46ec-b6d3-414b79977a7e/</guid><pubDate>Fri, 17 Apr 2026 00:00:00 GMT</pubDate><description>l1malwarebits.sys is a vulnerable kernel driver from the KeServiceDescriptorTable/vulnerable-drivers repository. The driver exposes dangerous kernel primitives to usermode.</description></item><item><title>Lallamon.sys</title><link>https://www.loldrivers.io/drivers/50de2fce-d9b5-4007-abef-22560e4e93b2/</link><guid>https://www.loldrivers.io/drivers/50de2fce-d9b5-4007-abef-22560e4e93b2/</guid><pubDate>Fri, 17 Apr 2026 00:00:00 GMT</pubDate><description>Lallamon.sys is a vulnerable kernel driver from the KeServiceDescriptorTable/vulnerable-drivers repository. The driver exposes dangerous kernel primitives to usermode.</description></item><item><title>lsigetwin_SliffDriver.sys</title><link>https://www.loldrivers.io/drivers/430f94b4-69e8-4541-bea7-329be7d283b7/</link><guid>https://www.loldrivers.io/drivers/430f94b4-69e8-4541-bea7-329be7d283b7/</guid><pubDate>Fri, 17 Apr 2026 00:00:00 GMT</pubDate><description>lsigetwin_SliffDriver.sys is a Microsoft-signed vulnerable kernel driver that exposes a \\.\SliffDriver device. Public research documents IOCTL 0x80002004 for mapping caller-supplied physical memory into user mode, enabling local privilege escalation when chained with kernel address discovery and virtual-to-physical translation primitives.</description></item><item><title>MemCtl.sys</title><link>https://www.loldrivers.io/drivers/ae2a6048-3896-4dd8-9eb1-a4a66104b0cf/</link><guid>https://www.loldrivers.io/drivers/ae2a6048-3896-4dd8-9eb1-a4a66104b0cf/</guid><pubDate>Fri, 17 Apr 2026 00:00:00 GMT</pubDate><description>MemCtl.sys is a vulnerable kernel driver from the KeServiceDescriptorTable/vulnerable-drivers repository. The driver exposes dangerous kernel primitives to usermode.</description></item><item><title>Mnemosyne.sys</title><link>https://www.loldrivers.io/drivers/24cc4f8d-a88d-4b2d-a912-bc773d12a524/</link><guid>https://www.loldrivers.io/drivers/24cc4f8d-a88d-4b2d-a912-bc773d12a524/</guid><pubDate>Fri, 17 Apr 2026 00:00:00 GMT</pubDate><description>Mnemosyne.sys is a vulnerable kernel driver from the KeServiceDescriptorTable/vulnerable-drivers repository. The driver exposes dangerous kernel primitives to usermode.</description></item><item><title>mst.sys</title><link>https://www.loldrivers.io/drivers/0e94f1a2-beab-4adb-9687-eb2719a201c9/</link><guid>https://www.loldrivers.io/drivers/0e94f1a2-beab-4adb-9687-eb2719a201c9/</guid><pubDate>Fri, 17 Apr 2026 00:00:00 GMT</pubDate><description>mst.sys is a vulnerable kernel driver from the KeServiceDescriptorTable/vulnerable-drivers repository. The driver exposes dangerous kernel primitives to usermode.</description></item><item><title>mtxC9CB.sys</title><link>https://www.loldrivers.io/drivers/b7bfe661-591a-45be-823d-ac6dae2edeed/</link><guid>https://www.loldrivers.io/drivers/b7bfe661-591a-45be-823d-ac6dae2edeed/</guid><pubDate>Fri, 17 Apr 2026 00:00:00 GMT</pubDate><description>mtxC9CB.sys is a vulnerable kernel driver from the KeServiceDescriptorTable/vulnerable-drivers repository. The driver exposes dangerous kernel primitives to usermode.</description></item><item><title>mtxmem.sys</title><link>https://www.loldrivers.io/drivers/7c766ce5-fa74-4080-907d-95f2f68d49e7/</link><guid>https://www.loldrivers.io/drivers/7c766ce5-fa74-4080-907d-95f2f68d49e7/</guid><pubDate>Fri, 17 Apr 2026 00:00:00 GMT</pubDate><description>mtxmem.sys is a vulnerable kernel driver from the KeServiceDescriptorTable/vulnerable-drivers repository. The driver exposes dangerous kernel primitives to usermode.</description></item><item><title>NetworkLocker_x64.sys</title><link>https://www.loldrivers.io/drivers/0e114b5b-7ec1-4fa3-ac93-e505f986547f/</link><guid>https://www.loldrivers.io/drivers/0e114b5b-7ec1-4fa3-ac93-e505f986547f/</guid><pubDate>Fri, 17 Apr 2026 00:00:00 GMT</pubDate><description>NetworkLocker_x64.sys is a vulnerable kernel driver from the KeServiceDescriptorTable/vulnerable-drivers repository. The driver exposes dangerous kernel primitives to usermode.</description></item><item><title>Novawave_Novabench_NovabenchDriverWin10.sys</title><link>https://www.loldrivers.io/drivers/c7789f3c-b638-4f66-a890-7605682306e7/</link><guid>https://www.loldrivers.io/drivers/c7789f3c-b638-4f66-a890-7605682306e7/</guid><pubDate>Fri, 17 Apr 2026 00:00:00 GMT</pubDate><description>Novawave_Novabench_NovabenchDriverWin10.sys is a vulnerable kernel driver from the KeServiceDescriptorTable/vulnerable-drivers repository. The driver exposes dangerous kernel primitives to usermode.</description></item><item><title>NPR0.sys</title><link>https://www.loldrivers.io/drivers/cf9ed92d-d39b-4562-a256-b36f6560ccfa/</link><guid>https://www.loldrivers.io/drivers/cf9ed92d-d39b-4562-a256-b36f6560ccfa/</guid><pubDate>Fri, 17 Apr 2026 00:00:00 GMT</pubDate><description>NPR0.sys is a vulnerable kernel driver from the KeServiceDescriptorTable/vulnerable-drivers repository. The driver exposes dangerous kernel primitives to usermode.</description></item><item><title>nxeng.sys</title><link>https://www.loldrivers.io/drivers/6f1d7635-0778-4f17-9c97-b80deca32510/</link><guid>https://www.loldrivers.io/drivers/6f1d7635-0778-4f17-9c97-b80deca32510/</guid><pubDate>Fri, 17 Apr 2026 00:00:00 GMT</pubDate><description>nxeng.sys is a vulnerable kernel driver from the KeServiceDescriptorTable/vulnerable-drivers repository. The driver exposes dangerous kernel primitives to usermode.</description></item><item><title>OAToolx64.sys</title><link>https://www.loldrivers.io/drivers/3a56286a-d6e2-4782-bd43-1e04869da8cc/</link><guid>https://www.loldrivers.io/drivers/3a56286a-d6e2-4782-bd43-1e04869da8cc/</guid><pubDate>Fri, 17 Apr 2026 00:00:00 GMT</pubDate><description>OAToolx64.sys is a vulnerable kernel driver from the KeServiceDescriptorTable/vulnerable-drivers repository. The driver exposes dangerous kernel primitives to usermode.</description></item><item><title>p2KGhmzsARY1.sys</title><link>https://www.loldrivers.io/drivers/90239ca5-500d-422a-a3e6-6b771b55b3eb/</link><guid>https://www.loldrivers.io/drivers/90239ca5-500d-422a-a3e6-6b771b55b3eb/</guid><pubDate>Fri, 17 Apr 2026 00:00:00 GMT</pubDate><description>p2KGhmzsARY1.sys is a vulnerable kernel driver from the KeServiceDescriptorTable/vulnerable-drivers repository. The driver exposes dangerous kernel primitives to usermode.</description></item><item><title>PMAD.sys</title><link>https://www.loldrivers.io/drivers/ec5012bb-789a-436d-be22-b343c331f7c7/</link><guid>https://www.loldrivers.io/drivers/ec5012bb-789a-436d-be22-b343c331f7c7/</guid><pubDate>Fri, 17 Apr 2026 00:00:00 GMT</pubDate><description>PMAD.sys is a vulnerable kernel driver from the KeServiceDescriptorTable/vulnerable-drivers repository. The driver exposes dangerous kernel primitives to usermode.</description></item><item><title>portwell.sys</title><link>https://www.loldrivers.io/drivers/84f92ac1-1e72-420d-9cc0-65c838b90a4d/</link><guid>https://www.loldrivers.io/drivers/84f92ac1-1e72-420d-9cc0-65c838b90a4d/</guid><pubDate>Fri, 17 Apr 2026 00:00:00 GMT</pubDate><description>portwell.sys is a kernel driver from Portwell Inc. (Taiwan) that exposes physical memory read/write via MmMapIoSpace. Portwell manufactures embedded computing platforms and industrial PCs. The driver is available in the KeServiceDescriptorTable/vulnerable-drivers repository.</description></item><item><title>ppa_x64.sys</title><link>https://www.loldrivers.io/drivers/d6dc9b52-9918-442d-b03a-f1f614aa4cce/</link><guid>https://www.loldrivers.io/drivers/d6dc9b52-9918-442d-b03a-f1f614aa4cce/</guid><pubDate>Fri, 17 Apr 2026 00:00:00 GMT</pubDate><description>ppa_x64.sys is a kernel driver by Remko Weijnen that provides physical memory access via the PhysicalMemory section object. The device name PhyMem indicates this is part of the PhyMem driver family, of which several variants are already tracked in LOLDrivers (phymem64.sys, Phymemx64.sys, phymem_ext64.sys). The driver is available in the KeServiceDescriptorTable/vulnerable-drivers repository.</description></item><item><title>Realtime Driver.sys</title><link>https://www.loldrivers.io/drivers/6882f954-e69b-464a-b7cf-0cda802d3257/</link><guid>https://www.loldrivers.io/drivers/6882f954-e69b-464a-b7cf-0cda802d3257/</guid><pubDate>Fri, 17 Apr 2026 00:00:00 GMT</pubDate><description>Realtime Driver.sys is a vulnerable kernel driver from the KeServiceDescriptorTable/vulnerable-drivers repository. The driver exposes dangerous kernel primitives to usermode.</description></item><item><title>RtsTpx.sys</title><link>https://www.loldrivers.io/drivers/610617d5-2566-4f55-b636-29a4ea576654/</link><guid>https://www.loldrivers.io/drivers/610617d5-2566-4f55-b636-29a4ea576654/</guid><pubDate>Fri, 17 Apr 2026 00:00:00 GMT</pubDate><description>RtsTpx.sys is a vulnerable kernel driver from the KeServiceDescriptorTable/vulnerable-drivers repository. The driver exposes dangerous kernel primitives to usermode.</description></item><item><title>sdrv_win_sliff.sys</title><link>https://www.loldrivers.io/drivers/f1dd9c41-2608-48e5-bb3e-191d56b34591/</link><guid>https://www.loldrivers.io/drivers/f1dd9c41-2608-48e5-bb3e-191d56b34591/</guid><pubDate>Fri, 17 Apr 2026 00:00:00 GMT</pubDate><description>sdrv_win_sliff.sys is a vulnerable kernel driver from the KeServiceDescriptorTable/vulnerable-drivers repository. The driver exposes dangerous kernel primitives to usermode.</description></item><item><title>signeddrv.sys</title><link>https://www.loldrivers.io/drivers/028aecb5-70d0-4423-87d7-f037a11ef1c9/</link><guid>https://www.loldrivers.io/drivers/028aecb5-70d0-4423-87d7-f037a11ef1c9/</guid><pubDate>Fri, 17 Apr 2026 00:00:00 GMT</pubDate><description>signeddrv.sys is a Microsoft-signed vulnerable kernel driver that exposes an unrestricted \\.\WinNotify device. Public research documents IOCTL 0x22200C for kernel base disclosure, IOCTL 0x222040 for arbitrary kernel read, and IOCTL 0x222044 for arbitrary kernel write, enabling local privilege escalation.</description></item><item><title>SIOCTL.sys</title><link>https://www.loldrivers.io/drivers/47e08b2f-7925-40c5-9bcf-0af348c07d33/</link><guid>https://www.loldrivers.io/drivers/47e08b2f-7925-40c5-9bcf-0af348c07d33/</guid><pubDate>Fri, 17 Apr 2026 00:00:00 GMT</pubDate><description>SIOCTL.sys is a vulnerable kernel driver from the KeServiceDescriptorTable/vulnerable-drivers repository. The driver exposes dangerous kernel primitives to usermode.</description></item><item><title>SONiXDDRx64.sys</title><link>https://www.loldrivers.io/drivers/9720d49d-c20f-479e-9284-2b3ad120fdf8/</link><guid>https://www.loldrivers.io/drivers/9720d49d-c20f-479e-9284-2b3ad120fdf8/</guid><pubDate>Fri, 17 Apr 2026 00:00:00 GMT</pubDate><description>SONiXDDRx64.sys is a vulnerable kernel driver from the KeServiceDescriptorTable/vulnerable-drivers repository. The driver exposes dangerous kernel primitives to usermode.</description></item><item><title>SparkIO.sys</title><link>https://www.loldrivers.io/drivers/2a9193cc-4e7e-4c8d-9cb4-040723e81841/</link><guid>https://www.loldrivers.io/drivers/2a9193cc-4e7e-4c8d-9cb4-040723e81841/</guid><pubDate>Fri, 17 Apr 2026 00:00:00 GMT</pubDate><description>SparkIO.sys is a WHQL-signed kernel driver from Clevo Co. (Taiwan ODM) that ships with Control Center 3.0 and Flexicharger utilities on Clevo-chassis laptops (XMG, Eluktronics, EVOO, Origin PC, System76, Sager, and others). CVE-2022-37415 (CVSS 7.8) documents an out-of-bounds write vulnerability. The driver exposes arbitrary physical memory read via MmMapIoSpace, unrestricted I/O port read/write, arbitrary PCI configuration space read/write, and SMBus/I2C read/write. The device is created with IoCreateDevice (no DACL) and IRP_MJ_CREATE returns STATUS_SUCCESS unconditionally with zero caller validation. A public PoC exists by alfarom256.</description></item><item><title>srswdrv.sys</title><link>https://www.loldrivers.io/drivers/5c4142a6-b287-4817-864f-152be08f7c48/</link><guid>https://www.loldrivers.io/drivers/5c4142a6-b287-4817-864f-152be08f7c48/</guid><pubDate>Fri, 17 Apr 2026 00:00:00 GMT</pubDate><description>srswdrv.sys is a vulnerable kernel driver from the KeServiceDescriptorTable/vulnerable-drivers repository. The driver exposes dangerous kernel primitives to usermode.</description></item><item><title>SvIoCtrlx64.sys</title><link>https://www.loldrivers.io/drivers/8d2f15a5-e71a-47ba-a391-55d1a1962368/</link><guid>https://www.loldrivers.io/drivers/8d2f15a5-e71a-47ba-a391-55d1a1962368/</guid><pubDate>Fri, 17 Apr 2026 00:00:00 GMT</pubDate><description>SvIoCtrlx64.sys is a vulnerable kernel driver from the KeServiceDescriptorTable/vulnerable-drivers repository. The driver exposes dangerous kernel primitives to usermode.</description></item><item><title>SysFile_X64.sys</title><link>https://www.loldrivers.io/drivers/1ce0aa79-8719-447c-908b-75547f2ccc98/</link><guid>https://www.loldrivers.io/drivers/1ce0aa79-8719-447c-908b-75547f2ccc98/</guid><pubDate>Fri, 17 Apr 2026 00:00:00 GMT</pubDate><description>SysFile_X64.sys is a vulnerable kernel driver from the KeServiceDescriptorTable/vulnerable-drivers repository. The driver exposes dangerous kernel primitives to usermode.</description></item><item><title>SysInfoX64.sys</title><link>https://www.loldrivers.io/drivers/1dd9bcd1-0090-4561-bfc4-481c3d139c81/</link><guid>https://www.loldrivers.io/drivers/1dd9bcd1-0090-4561-bfc4-481c3d139c81/</guid><pubDate>Fri, 17 Apr 2026 00:00:00 GMT</pubDate><description>SysInfoX64.sys is a vulnerable kernel driver from the KeServiceDescriptorTable/vulnerable-drivers repository. The driver exposes dangerous kernel primitives to usermode.</description></item><item><title>TBT_Force_Power_Control_Access64.sys</title><link>https://www.loldrivers.io/drivers/408964b3-1799-425b-92bf-465c72a272d1/</link><guid>https://www.loldrivers.io/drivers/408964b3-1799-425b-92bf-465c72a272d1/</guid><pubDate>Fri, 17 Apr 2026 00:00:00 GMT</pubDate><description>TBT_Force_Power_Control_Access64.sys is a Thunderbolt force power control driver from Wistron Corporation that exposes physical memory read/write via MmMapIoSpace. Wistron is a major Taiwan-based OEM/ODM. Another Wistron driver (WiRwaDrv.sys) is already tracked in LOLDrivers. The driver is available in the KeServiceDescriptorTable/vulnerable-drivers repository.</description></item><item><title>UDDB2B6.sys</title><link>https://www.loldrivers.io/drivers/886af494-4087-48c9-b48f-53e638d6f62e/</link><guid>https://www.loldrivers.io/drivers/886af494-4087-48c9-b48f-53e638d6f62e/</guid><pubDate>Fri, 17 Apr 2026 00:00:00 GMT</pubDate><description>UDDB2B6.sys is a TechPowerUp kernel driver (GPU-Z variant) that exposes I/O port read/write, MSR read/write, MmMapIoSpace map/unmap/read/write, and PCI configuration space read/write. TechPowerUp has a history of vulnerable kernel drivers including GPU-Z.sys (CVE-2019-7245, CVE-2025-5324) and ThrottleStop.sys (CVE-2025-7771). The driver is available in the KeServiceDescriptorTable/vulnerable-drivers repository.</description></item><item><title>watabe.sys</title><link>https://www.loldrivers.io/drivers/549d3563-74ce-4d84-844c-8d985886373c/</link><guid>https://www.loldrivers.io/drivers/549d3563-74ce-4d84-844c-8d985886373c/</guid><pubDate>Fri, 17 Apr 2026 00:00:00 GMT</pubDate><description>watabe.sys is a vulnerable kernel driver from the KeServiceDescriptorTable/vulnerable-drivers repository. The driver exposes dangerous kernel primitives to usermode.</description></item><item><title>wdisvhost.sys</title><link>https://www.loldrivers.io/drivers/894bd2db-1d93-4b3d-8e4d-7dac29382cb9/</link><guid>https://www.loldrivers.io/drivers/894bd2db-1d93-4b3d-8e4d-7dac29382cb9/</guid><pubDate>Fri, 17 Apr 2026 00:00:00 GMT</pubDate><description>wdisvhost.sys is a vulnerable kernel driver from the KeServiceDescriptorTable/vulnerable-drivers repository. The driver exposes dangerous kernel primitives to usermode.</description></item><item><title>whql.sys</title><link>https://www.loldrivers.io/drivers/c366ee89-97ae-4523-b635-e05769384bd3/</link><guid>https://www.loldrivers.io/drivers/c366ee89-97ae-4523-b635-e05769384bd3/</guid><pubDate>Fri, 17 Apr 2026 00:00:00 GMT</pubDate><description>whql.sys is a vulnerable kernel driver from the KeServiceDescriptorTable/vulnerable-drivers repository. The driver exposes dangerous kernel primitives to usermode.</description></item><item><title>Windows_CPU_Temperature_Component.sys</title><link>https://www.loldrivers.io/drivers/52955eb1-8cf4-41f3-b998-5e2e6d3aa258/</link><guid>https://www.loldrivers.io/drivers/52955eb1-8cf4-41f3-b998-5e2e6d3aa258/</guid><pubDate>Fri, 17 Apr 2026 00:00:00 GMT</pubDate><description>Windows_CPU_Temperature_Component.sys is a vulnerable kernel driver from the KeServiceDescriptorTable/vulnerable-drivers repository. The driver exposes dangerous kernel primitives to usermode.</description></item><item><title>Windows-Memory-Informer.sys</title><link>https://www.loldrivers.io/drivers/e354b869-e817-4f9f-8027-a3d5bfb3689b/</link><guid>https://www.loldrivers.io/drivers/e354b869-e817-4f9f-8027-a3d5bfb3689b/</guid><pubDate>Fri, 17 Apr 2026 00:00:00 GMT</pubDate><description>Windows-Memory-Informer.sys is a vulnerable kernel driver from the KeServiceDescriptorTable/vulnerable-drivers repository. The driver exposes dangerous kernel primitives to usermode.</description></item><item><title>XLHA.sys</title><link>https://www.loldrivers.io/drivers/d0de6c54-2dd8-4e32-a2a7-c6c26dcd2a0f/</link><guid>https://www.loldrivers.io/drivers/d0de6c54-2dd8-4e32-a2a7-c6c26dcd2a0f/</guid><pubDate>Fri, 17 Apr 2026 00:00:00 GMT</pubDate><description>XLHA.sys is a kernel driver from LG Electronics Inc. that exposes physical memory read/write via MmMapIoSpace and MSR read. Two other LG LHA.sys variants are already tracked in LOLDrivers. The driver is available in the KeServiceDescriptorTable/vulnerable-drivers repository.</description></item><item><title>AdvCare.sys</title><link>https://www.loldrivers.io/drivers/658a906e-82d3-4c78-a63b-ddddeeb3f452/</link><guid>https://www.loldrivers.io/drivers/658a906e-82d3-4c78-a63b-ddddeeb3f452/</guid><pubDate>Mon, 13 Apr 2026 00:00:00 GMT</pubDate><description>AdvCare.sys is a legacy hardware health monitor driver from Advantech Co., Ltd. for industrial PCs and embedded boards. The driver exposes arbitrary MSR read/write (wrmsr/rdmsr with no validation), arbitrary physical memory read/write via MmMapIoSpace, unrestricted port I/O across all 65536 ports, and PCI configuration space read/write via HalGetBusDataByOffset/HalSetBusDataByOffset. The device is created with IoCreateDevice (no DACL) and IRP_MJ_CREATE returns STATUS_SUCCESS unconditionally with zero caller validation -- no admin check, no token check, no integrity check. Any unprivileged local user can open the device and invoke every primitive. The driver is also available in the KeServiceDescriptorTable/vulnerable-drivers repository on GitHub.</description></item><item><title>CardIo64.sys</title><link>https://www.loldrivers.io/drivers/97e3077a-ca57-4f45-ba7c-f63dc9c4ea32/</link><guid>https://www.loldrivers.io/drivers/97e3077a-ca57-4f45-ba7c-f63dc9c4ea32/</guid><pubDate>Mon, 13 Apr 2026 00:00:00 GMT</pubDate><description>CardIo64.sys is a kernel driver from ICP DAS Co., LTD. (Taiwan), an industrial automation and I/O board manufacturer. The driver exposes arbitrary physical memory read/write via MmMapIoSpace, port I/O read/write (8/16/32-bit), and PCI bus data read/write via HalGetBusDataByOffset and HalSetBusDataByOffset. The driver is only 13KB and is also available in the KeServiceDescriptorTable/vulnerable-drivers repository on GitHub.</description></item><item><title>cpqsysio64.sys</title><link>https://www.loldrivers.io/drivers/e41d5471-c4b8-48da-bdb7-e462008c2e78/</link><guid>https://www.loldrivers.io/drivers/e41d5471-c4b8-48da-bdb7-e462008c2e78/</guid><pubDate>Mon, 13 Apr 2026 00:00:00 GMT</pubDate><description>cpqsysio64.sys is a Hewlett-Packard physical-memory driver distributed with ProLiant support and firmware utilities. The tracked 4.5.0.0 and 4.6.0.0 builds handle IOCTL 0x152EF0 by accepting a caller-supplied physical address and length, mapping that range with MmMapIoSpace, and copying from it without constraining the requested physical range. An administrator with device access can read arbitrary physical memory, disclose kernel-sensitive data, and recover addresses that undermine kernel address randomization.</description></item><item><title>DsArk64.sys</title><link>https://www.loldrivers.io/drivers/399fb787-5b06-46f0-86cb-dff7374bb015/</link><guid>https://www.loldrivers.io/drivers/399fb787-5b06-46f0-86cb-dff7374bb015/</guid><pubDate>Mon, 13 Apr 2026 00:00:00 GMT</pubDate><description>DsArk64.sys is a WHQL Microsoft-signed anti-rootkit kernel driver from Qihoo 360 Total Security. It exposes kernel-level process termination via ZwTerminateProcess from Ring 0 (kills PPL-protected processes), arbitrary kernel memory read (512 bytes), and arbitrary kernel memory write (32 bytes). The driver gates device access behind a custom Authenticode signing check that validates the calling process PE signature against Qihoo root certificates. This check is fully bypassed via process hollowing into any Qihoo-signed executable (freely downloadable from 360.cn). The process kill IOCTL (0x80863008) requires no encryption or additional auth beyond the device open -- just a raw 4-byte PID. The kernel R/W IOCTLs use AES-128-CBC with a static key embedded in the binary. Initialization requires setting registry key HKLM\SYSTEM\CCS\Services\360FsFlt\daboot to 1.</description></item><item><title>dtr_ec.sys</title><link>https://www.loldrivers.io/drivers/a2177b22-0401-4c31-8ae4-40a7e2a53653/</link><guid>https://www.loldrivers.io/drivers/a2177b22-0401-4c31-8ae4-40a7e2a53653/</guid><pubDate>Mon, 13 Apr 2026 00:00:00 GMT</pubDate><description>dtr_ec.sys is a Dell kernel driver that ships as part of the Dell Feature Enhancement Pack (DFEP) on Dell laptops and desktops. The driver provides unrestricted read/write access to Embedded Controller (EC) registers across 5 ACPI address spaces from usermode with no validation on the register addresses or values. The Embedded Controller manages critical hardware functions including thermal management, battery charging, fan control, power states, and keyboard input. Unrestricted EC register access allows manipulation of thermal thresholds to cause hardware damage or forced shutdowns, modification of fan speed controls, interference with battery charging logic, and alteration of power management behavior. Dell PSIRT has confirmed the vulnerability and triaged it as P2 severity on Bugcrowd.</description></item><item><title>kdhacker64_ev.sys</title><link>https://www.loldrivers.io/drivers/a6dd3aef-d3a7-4c72-abcd-e633e0c0706c/</link><guid>https://www.loldrivers.io/drivers/a6dd3aef-d3a7-4c72-abcd-e633e0c0706c/</guid><pubDate>Mon, 13 Apr 2026 00:00:00 GMT</pubDate><description>kdhacker64_ev.sys is a kernel driver from Beijing Kingsoft Security software bundled with Kingsoft AntiVirus and Liebao Browser. The driver exposes a kernel heap buffer overflow via IOCTL 0x120140 with approximately 512 bytes of overflow into adjacent kernel pool allocations. The root cause is a size validation mismatch -- input is validated at 0x488 bytes per element but only 0x248 bytes are allocated per element. RtlInitUnicodeString is called on user-controlled buffers without null terminator bounds checking, producing oversized ANSI strings that overflow 64-byte destination buffers. No authentication is required to access the device. The driver also includes TDI hooks for TCP/UDP/RawIP interception, process creation notification callbacks, filesystem filter attachments to NTFS/FAT/CDFS, camera device monitoring, and HTTP header parsing. Other Kingsoft drivers (ksapi.sys, mydrivers.sys) are already tracked in LOLDrivers.</description></item><item><title>ArgusMonitor.sys</title><link>https://www.loldrivers.io/drivers/08fbd284-7ad2-466d-b55f-6d5a7d07aca5/</link><guid>https://www.loldrivers.io/drivers/08fbd284-7ad2-466d-b55f-6d5a7d07aca5/</guid><pubDate>Fri, 10 Apr 2026 00:00:00 GMT</pubDate><description>ArgusMonitor.sys is the kernel driver for the Argus Monitor hardware temperature monitoring and fan control application by Argotronic UG (Germany). The driver exposes 47 IOCTLs providing arbitrary physical memory read/write via MmMapIoSpace (32 map slots, up to 128KB) with a single-shot read primitive that bypasses the address restriction (busNum=0xFF), unrestricted port I/O (any port 0x0000-0xFFFF), PCI configuration space read/write via HalGetBusDataByOffset and HalSetBusDataByOffset, MSR read/write with a whitelist that blocks IA32_LSTAR but allows IA32_MISC_ENABLE write (can disable NX/XD system-wide), and I2C/SMBus access via MMIO bit-banging. The driver uses IoCreateDevice with no DACL and IRP_MJ_CREATE returns STATUS_SUCCESS immediately with no caller validation. A handshake IOCTL accepts a user-chosen 0x200-byte XOR keypad (sending all zeros effectively disables the XOR layer). WHQL attestation signed with an active Microsoft certificate. KASLR bypass confirmed via physical memory PE header scan. Loads on any x64 Windows without ArgusMonitor software.</description></item><item><title>Astra64.sys</title><link>https://www.loldrivers.io/drivers/5904f3a1-2e0c-4746-8078-8ada66a5cb08/</link><guid>https://www.loldrivers.io/drivers/5904f3a1-2e0c-4746-8078-8ada66a5cb08/</guid><pubDate>Fri, 10 Apr 2026 00:00:00 GMT</pubDate><description>ASTRA64.sys is the kernel driver for the ASTRA32 system information tool by Sysinfo Lab (EnTech Taiwan). The driver exposes 31 IOCTLs with zero validation on all parameters including arbitrary physical memory read/write via ZwOpenSection and ZwMapViewOfSection on Device\PhysicalMemory with PAGE_READWRITE, arbitrary port I/O via HalTranslateBusAddress, arbitrary MSR read via rdmsr (enables KASLR bypass via IA32_LSTAR), PCI configuration space read via HalGetBusDataByOffset, and MMIO physical memory mapping via MmMapIoSpace. No authentication gate, no DACL restrictions (plain IoCreateDevice). Loads on any x64 Windows system. EnTech Taiwan also produces TVicPort and softEngine drivers which share similar low-level hardware access patterns. Listed in Eclypsium Screwed-Drivers research.</description></item><item><title>nipalk.sys</title><link>https://www.loldrivers.io/drivers/5ff0ca63-fff8-4c2d-ac04-bb09fc84259f/</link><guid>https://www.loldrivers.io/drivers/5ff0ca63-fff8-4c2d-ac04-bb09fc84259f/</guid><pubDate>Fri, 10 Apr 2026 00:00:00 GMT</pubDate><description>nipalk.sys is the NI-PAL core kernel driver. The tracked 18.0.0f0 build is within NI-PAL versions before 20.0.1f0 affected by CVE-2021-38304, where improper input validation can allow a local user to escalate privileges. The separately tracked 25.8 build is not attributed to that CVE; exact analysis of that build found physical-memory mapping, virtual-to-physical translation, DMA allocation, bus access, and PCI configuration operations reachable through its IOCTL service gateway.</description></item><item><title>PoisonX.sys</title><link>https://www.loldrivers.io/drivers/fc3467c3-6109-447d-b438-7a4276c3d8e5/</link><guid>https://www.loldrivers.io/drivers/fc3467c3-6109-447d-b438-7a4276c3d8e5/</guid><pubDate>Fri, 10 Apr 2026 00:00:00 GMT</pubDate><description>A Microsoft-signed vulnerable driver used in BYOVD attacks to terminate protected processes, including EDR solutions such as CrowdStrike Falcon. The driver exposes an IOCTL that allows arbitrary process termination from user mode by passing a PID.</description></item><item><title>TcIo.sys</title><link>https://www.loldrivers.io/drivers/12998ebb-8c74-4e44-89a2-2a71c0f6e92b/</link><guid>https://www.loldrivers.io/drivers/12998ebb-8c74-4e44-89a2-2a71c0f6e92b/</guid><pubDate>Fri, 10 Apr 2026 00:00:00 GMT</pubDate><description>TcIo.sys and TcRouter.sys are WHQL Microsoft-signed kernel drivers from Beckhoff Automation GmbH (TwinCAT 3 Industrial Automation Runtime). TcIo.sys exposes arbitrary physical memory read/write via ZwOpenSection on Device\PhysicalMemory, arbitrary MMIO mapping via MmMapIoSpace, PCI configuration space read/write via HalGetBusDataByOffset and HalSetBusDataByOffset, and full PCI BAR probing and mapping. TcRouter.sys exposes arbitrary port I/O via direct ring-0 in/out instructions. Both drivers use plain IoCreateDevice with no DACL and have no caller validation on IRP_MJ_CREATE. All IOCTLs use METHOD_NEITHER with FILE_ANY_ACCESS. No hardware gate -- drivers load on any x64 Windows without Beckhoff hardware. CVE-2018-7502 was assigned for an untrusted pointer dereference in IOCTL 0x222206 affecting 19 drivers in the TwinCAT family (CISA advisory ICSA-18-081-02, Source Incite SRC-2018-0007). The physical memory and port I/O primitives described here go beyond the scope of CVE-2018-7502. 18 related drivers share the same codebase and certificate.</description></item><item><title>TRIXX.sys</title><link>https://www.loldrivers.io/drivers/f0a02666-44f6-4174-a7c6-d006481a340f/</link><guid>https://www.loldrivers.io/drivers/f0a02666-44f6-4174-a7c6-d006481a340f/</guid><pubDate>Tue, 07 Apr 2026 00:00:00 GMT</pubDate><description>TRIXX.sys is a shared utility kernel driver distributed by TechPowerUp LLC with Sapphire TRIXX and GPU-Z. The driver provides completely unrestricted hardware access from usermode through 16+ IOCTLs with zero validation on hardware parameters, including arbitrary port I/O read/write, arbitrary PCI configuration space read/write via HalGetBusDataByOffset/HalSetBusDataByOffset, MMIO BAR mapping via MmMapIoSpace, and MMIO read/write through mapped BARs. Physical memory read/write is achievable by remapping a PCI device BAR to a target physical address then mapping it via MmMapIoSpace. The driver creates its device dynamically based on the Windows service name and has no hardware dependency, loading on any x64 Windows system. TechPowerUp has a history of vulnerable kernel drivers including GPU-Z.sys (CVE-2019-7245, CVE-2025-5324) and ThrottleStop.sys (CVE-2025-7771) which expose the same MmMapIoSpace primitive. Fresh EV code signing certificate valid until April 2028 with zero AV detections.</description></item><item><title>WDTKernel.sys</title><link>https://www.loldrivers.io/drivers/08adabb3-7336-43de-a980-e23a55081f19/</link><guid>https://www.loldrivers.io/drivers/08adabb3-7336-43de-a980-e23a55081f19/</guid><pubDate>Tue, 07 Apr 2026 00:00:00 GMT</pubDate><description>WDTKernel.sys is a Dell Watchdog Timer Kernel Driver that exposes 12 IOCTLs for arbitrary physical memory read/write via MmMapIoSpace with zero validation on user-supplied physical addresses. It also provides 12 IOCTLs for unrestricted I/O port access and 2 IOCTLs for PCI configuration space access. The driver was WHQL attestation signed through Microsoft and is distributed via the Microsoft Update Catalog. VMware Carbon Black TAU mentioned this driver in their October 2023 research but classified it as not vulnerable in terms of access control because its INF sets an SDDL restricting device access to Administrators and SYSTEM. The arbitrary physical memory R/W via MmMapIoSpace was not analyzed or documented by TAU. Device path is \\.\__WDT__. Suitable for BYOVD attacks where the attacker already has admin privileges and needs kernel-level memory access to bypass EDR.</description></item><item><title>CorMem.sys</title><link>https://www.loldrivers.io/drivers/a7c3e2d1-8f4b-4e6a-b5d9-3c1f0e7a9b82/</link><guid>https://www.loldrivers.io/drivers/a7c3e2d1-8f4b-4e6a-b5d9-3c1f0e7a9b82/</guid><pubDate>Mon, 06 Apr 2026 00:00:00 GMT</pubDate><description>Teledyne Digital Imaging CorMem.sys (Sapera Memory Manager) exposes physical memory read/write, contiguous memory allocation, and I/O port access to user-mode processes via CorMem.dll wrapper functions. The driver provides 36 exported functions including CorMemGetPhysMemory, CorMemMapPhysMemory, CorMemAllocPhysMemory, CorMemReadIo, and CorMemWriteIo. Actively abused for BYOVD with 0/71 VT detection. Execution parents include Cobalt Strike/IcedID malware and game cheat kernel loaders.</description></item><item><title>dpmemio.sys</title><link>https://www.loldrivers.io/drivers/741677e9-20d5-40e5-9cd2-3bf2beb76322/</link><guid>https://www.loldrivers.io/drivers/741677e9-20d5-40e5-9cd2-3bf2beb76322/</guid><pubDate>Mon, 06 Apr 2026 00:00:00 GMT</pubDate><description>ET&amp;T Technology Co., Ltd. dpmemio.sys (ClevoECView) is a 12KB driver with only 9 imports that provides completely unrestricted arbitrary physical memory read/write and I/O port access with no authentication, no ACL, no address validation, and no size validation. MmUnmapIoSpace is not even imported, meaning every MmMapIoSpace call permanently leaks a system PTE mapping. An additional bug exists where MOVSXD sign-extension on a 32-bit UserBufferPtr provides a write-to-kernel-VA primitive. IOCTLs exposed via \\.\dpMemIO include 0xC80A2420 (arbitrary physical memory READ via MmMapIoSpace), 0xC80A2424 (arbitrary physical memory WRITE via MmMapIoSpace), 0xC80A2410/0xC80A2414 (I/O port read/write byte), 0xC80A2418/0xC80A241C (I/O port read/write variable size), and 0xC80A2428 (version/ping). VeriSign signed with a revoked certificate.</description></item><item><title>DriversCloud_amd64.sys</title><link>https://www.loldrivers.io/drivers/b3f7c8d2-4a19-4e5b-9d6c-2f8e1a3b7c04/</link><guid>https://www.loldrivers.io/drivers/b3f7c8d2-4a19-4e5b-9d6c-2f8e1a3b7c04/</guid><pubDate>Mon, 06 Apr 2026 00:00:00 GMT</pubDate><description>CYBELSOFT DriversCloud_amd64.sys exposes 7 IOCTLs with no access checks and a zero security descriptor on the device object, meaning any user (including low-integrity processes) can open a handle. Primitives include arbitrary physical memory read via MmMapIoSpace (up to 2MB per call), arbitrary MSR read/write (including IA32_LSTAR for instant kernel code execution), arbitrary I/O port read/write, and arbitrary PCI configuration space read/write. A full LSTAR hijack PoC with crash-safe ROP restore has been demonstrated. The developer acknowledged the issue and is working on a rewritten driver.</description></item><item><title>SIVX64.sys</title><link>https://www.loldrivers.io/drivers/31439f28-4616-4ee1-a6b7-1cf742127909/</link><guid>https://www.loldrivers.io/drivers/31439f28-4616-4ee1-a6b7-1cf742127909/</guid><pubDate>Mon, 06 Apr 2026 00:00:00 GMT</pubDate><description>Ray Hinchliffe SIV (System Information Viewer) SIVX64.sys v5.85 dynamically resolves MmMapIoSpace and MmMapIoSpaceEx via MmGetSystemRoutineAddress at runtime (neither appears in the IAT), evading static import-based scanning. The driver exposes multiple privileged IOCTL primitives via \\.\SIVDRIVER including arbitrary physical memory mapped read/write (Cmd 0x14, critical), physical memory read via scatter-gather (Cmd 0x10) and bulk MDL (Cmd 0x13), MSR read/write on a whitelisted subset (Cmd 0x08/0x0C), unrestricted I/O port read/scan (Cmd 0x44/0x50), and unrestricted PCI configuration space read (Cmd 0x48). WHQL signed by Microsoft Windows Hardware Compatibility Publisher; loads despite HVCI.</description></item><item><title>KslD.sys</title><link>https://www.loldrivers.io/drivers/57822c56-6531-4a2e-afbf-96f77dc5fcaf/</link><guid>https://www.loldrivers.io/drivers/57822c56-6531-4a2e-afbf-96f77dc5fcaf/</guid><pubDate>Thu, 26 Mar 2026 00:00:00 GMT</pubDate><description>KslD.sys is a Microsoft-signed Windows Defender support driver that can be abused for kernel memory access after its SharedState process-name check is redirected to an attacker-controlled process. Public research documents IOCTL 0x222044 as exposing physical and virtual memory read primitives that can support KASLR bypass, token discovery, and LSASS/PPL bypass workflows.</description></item><item><title>athpexnt.sys</title><link>https://www.loldrivers.io/drivers/f4e00816-97a8-4c2d-b990-9812f16fe3d3/</link><guid>https://www.loldrivers.io/drivers/f4e00816-97a8-4c2d-b990-9812f16fe3d3/</guid><pubDate>Fri, 20 Mar 2026 00:00:00 GMT</pubDate><description>AhnLab kernel driver exposing arbitrary physical memory read/write via IOCTL 0x81000000. Device accessible at \\.\ATHpEx. Signed by AhnLab Inc. with VeriSign certificate (first seen 2014). Zero detections (0/73) on VirusTotal but exploitable for privilege escalation by mapping attacker-controlled physical memory into kernel address space.</description></item><item><title>CSAgent.sys</title><link>https://www.loldrivers.io/drivers/6c84d133-c619-4deb-a91a-5cf05e4cb7c2/</link><guid>https://www.loldrivers.io/drivers/6c84d133-c619-4deb-a91a-5cf05e4cb7c2/</guid><pubDate>Fri, 20 Mar 2026 00:00:00 GMT</pubDate><description>AbyssWorker rootkit masquerading as a CrowdStrike Falcon sensor driver (CSAgent.sys). Signed with a revoked certificate from Shenzhen yundian Technology Co., Ltd. This is a fully malicious driver that blinds security products by stripping handles, terminating processes, and removing notification callbacks. Identified in ESET EDR killers research (March 2026) deployed alongside Medusa ransomware via the HEARTCRYPT packer.</description></item><item><title>HwRwDrv.sys</title><link>https://www.loldrivers.io/drivers/81211b5b-36a7-41d6-a6e3-8e43cf7d0405/</link><guid>https://www.loldrivers.io/drivers/81211b5b-36a7-41d6-a6e3-8e43cf7d0405/</guid><pubDate>Fri, 20 Mar 2026 00:00:00 GMT</pubDate><description>Hardware read/write driver signed by a revoked Certum certificate (Open Source Developer, Jun Liu). Provides arbitrary physical memory read/write and PCI bus data access. Identified in ESET EDR killers research (March 2026) with 174 execution parents indicating widespread abuse by threat actors to disable EDR products.</description></item><item><title>PDFWKRNL.sys</title><link>https://www.loldrivers.io/drivers/ed27c0b8-6177-4132-a7af-5c15bcb386f3/</link><guid>https://www.loldrivers.io/drivers/ed27c0b8-6177-4132-a7af-5c15bcb386f3/</guid><pubDate>Fri, 20 Mar 2026 00:00:00 GMT</pubDate><description>AMD USB-C Power Delivery Firmware Update Kernel Library driver with arbitrary physical memory read/write capabilities. Identified in ESET EDR killers research (March 2026) as actively abused by threat actors to disable EDR products.</description></item><item><title>rspot.sys</title><link>https://www.loldrivers.io/drivers/d9a9fd72-e789-4bba-9b96-549b123e5c40/</link><guid>https://www.loldrivers.io/drivers/d9a9fd72-e789-4bba-9b96-549b123e5c40/</guid><pubDate>Fri, 20 Mar 2026 00:00:00 GMT</pubDate><description>Rising Antivirus rspot.sys driver with kernel-level process termination capabilities. Identified in ESET EDR killers research (March 2026) as actively abused by threat actors to disable EDR products.</description></item><item><title>shimano32.sys</title><link>https://www.loldrivers.io/drivers/8d23f7e6-341a-431e-9dc1-bc797773d411/</link><guid>https://www.loldrivers.io/drivers/8d23f7e6-341a-431e-9dc1-bc797773d411/</guid><pubDate>Fri, 20 Mar 2026 00:00:00 GMT</pubDate><description>HyperTech DNP CrackProof DRM kernel drivers (32-bit and 64-bit variants) from Shimano E-TUBE Project. Expose EPROCESS manipulation IOCTLs (0xAA013880, 0xAA013884, 0xAA013888) similar to capcom.sys exploitation technique. Device accessible at \\.\Htsysm4EFB. Zero detections (0/72 and 0/73) on VirusTotal. Signed by Microsoft WHCP via HyperTech DNP CrackProof (Japanese DRM vendor).</description></item><item><title>STProcessMonitor.sys</title><link>https://www.loldrivers.io/drivers/0712c54c-69fd-41f2-950a-da678ac51246/</link><guid>https://www.loldrivers.io/drivers/0712c54c-69fd-41f2-950a-da678ac51246/</guid><pubDate>Fri, 20 Mar 2026 00:00:00 GMT</pubDate><description>Safetica STProcessMonitor / ProcessMonitorDriver.sys exposes process-termination functionality through vulnerable IOCTL paths documented in public BYOVD research. The tracked samples include the 11.26.18.0 build and the legacy 11.11.4.0 build; public research notes that affected versions can be abused to terminate endpoint security processes from kernel context.</description></item><item><title>thelper.sys</title><link>https://www.loldrivers.io/drivers/4c009d0a-8dfa-49f7-b043-b9cef3b01101/</link><guid>https://www.loldrivers.io/drivers/4c009d0a-8dfa-49f7-b043-b9cef3b01101/</guid><pubDate>Fri, 20 Mar 2026 00:00:00 GMT</pubDate><description>OCular THelper driver with arbitrary kernel memory read/write and process manipulation capabilities. Identified in ESET EDR killers research (March 2026) with 46 execution parents linked to AgentStp campaigns abusing the driver to disable EDR products.</description></item><item><title>tm_filter.sys</title><link>https://www.loldrivers.io/drivers/651d1cdc-3e13-405f-b8b3-65cc70cef5a8/</link><guid>https://www.loldrivers.io/drivers/651d1cdc-3e13-405f-b8b3-65cc70cef5a8/</guid><pubDate>Fri, 20 Mar 2026 00:00:00 GMT</pubDate><description>Teramind Inc. kernel-mode filter drivers (tm_filter.sys and tmfsdrv2.sys) providing kernel-level input capture including keylogging and screen capture capabilities. Both signed by DigiCert under Teramind Inc. certificate. Execution parents point to teramind_agent MSI installer. Abused by threat actors for stealth monitoring operations. tmfsdrv2.sys has 1/73 detections on VirusTotal.</description></item><item><title>TVicPort64.sys</title><link>https://www.loldrivers.io/drivers/b4f3a1c2-e8d7-4f92-a301-5c6d9e0b1a2f/</link><guid>https://www.loldrivers.io/drivers/b4f3a1c2-e8d7-4f92-a301-5c6d9e0b1a2f/</guid><pubDate>Fri, 13 Feb 2026 00:00:00 GMT</pubDate><description>Load TVicPort64.sys kernel driver. Once loaded, device \\.\TVicPortDevice0 is accessible from any integrity level (no DACL). Send IOCTL 0x80002008 to map arbitrary physical memory into user-mode VA space via ZwMapViewOfSection and perform token stealing for LPE to SYSTEM.</description></item><item><title>BdApiUtil.sys</title><link>https://www.loldrivers.io/drivers/708650ed-c497-48be-97bc-9edd48cf2a1a/</link><guid>https://www.loldrivers.io/drivers/708650ed-c497-48be-97bc-9edd48cf2a1a/</guid><pubDate>Tue, 09 Dec 2025 00:00:00 GMT</pubDate><description>Driver can be used to load unsigned drivers. IOCTL code which takes a PID and terminates it (arbitrary process termination). Admin privileges required to install the driver, but if it&apos;s already installed, can be called by any user (non admin).</description></item><item><title>termdd.sys</title><link>https://www.loldrivers.io/drivers/ef848b1c-e197-4f98-aa19-4580f41a98b8/</link><guid>https://www.loldrivers.io/drivers/ef848b1c-e197-4f98-aa19-4580f41a98b8/</guid><pubDate>Fri, 07 Nov 2025 00:00:00 GMT</pubDate><description>A vulnerable kernel driver that can be used to disable Code Integrity</description></item><item><title>hlpdrv.sys</title><link>https://www.loldrivers.io/drivers/73bd234a-6c4f-4304-9e7d-5bc7a3f263e2/</link><guid>https://www.loldrivers.io/drivers/73bd234a-6c4f-4304-9e7d-5bc7a3f263e2/</guid><pubDate>Mon, 27 Oct 2025 00:00:00 GMT</pubDate><description>hlpdrv.sys is a malicious driver used to disable Windows Defender by modifying registry settings. This driver has been observed in Akira ransomware campaigns, where it is deployed to facilitate AV/EDR evasion or disablement through a Bring Your Own Vulnerable Driver (BYOVD) exploitation chain. The malware modifies the DisableAntiSpyware registry key via regedit.exe execution.</description></item><item><title>burntcigar.sys</title><link>https://www.loldrivers.io/drivers/bb20edec-ecd4-4acd-9ad2-e4559748b336/</link><guid>https://www.loldrivers.io/drivers/bb20edec-ecd4-4acd-9ad2-e4559748b336/</guid><pubDate>Thu, 09 Oct 2025 00:00:00 GMT</pubDate><description>BurntCigar (aka POORTRY) is a malicious kernel-mode rootkit driver used by multiple ransomware groups including Cuba, BlackCat, Medusa, LockBit, and RansomHub. Designed to disable and remove EDR solutions by terminating security processes and deleting critical security software files. VMProtect-packed driver signed with stolen Blueone Technology certificate. Detected by 32.9% of AV engines. Facilitates ransomware deployment by rendering systems defenseless.</description></item><item><title>changsha</title><link>https://www.loldrivers.io/drivers/636d30fd-2b95-4dc2-a413-be0e43d1482c/</link><guid>https://www.loldrivers.io/drivers/636d30fd-2b95-4dc2-a413-be0e43d1482c/</guid><pubDate>Thu, 09 Oct 2025 00:00:00 GMT</pubDate><description>Malicious rootkit masquerading as legitimate CrowdStrike Falcon Sensor driver (CSAgent.sys). Signed with stolen/expired Chinese certificate from 2015. Detected by 61.6% of AV engines as Rootkit.Win64.Agent and Trojan:Win64/AVTamper. Used to establish kernel-level persistence while evading detection by impersonating trusted security software.</description></item><item><title>BdApiUtil64.sys</title><link>https://www.loldrivers.io/drivers/f8ed41ef-18f0-441c-99b8-def062214d0e/</link><guid>https://www.loldrivers.io/drivers/f8ed41ef-18f0-441c-99b8-def062214d0e/</guid><pubDate>Thu, 18 Sep 2025 00:00:00 GMT</pubDate><description>Driver can be used to load unsigned drivers</description></item><item><title>K7RKScan.sys</title><link>https://www.loldrivers.io/drivers/9f88300d-e607-4e50-8626-fd799439e049/</link><guid>https://www.loldrivers.io/drivers/9f88300d-e607-4e50-8626-fd799439e049/</guid><pubDate>Thu, 18 Sep 2025 00:00:00 GMT</pubDate><description>Driver can be used to load unsigned drivers</description></item><item><title>K7RKScan.sys</title><link>https://www.loldrivers.io/drivers/bd580aba-a804-4afc-adb3-b8ce342c78f6/</link><guid>https://www.loldrivers.io/drivers/bd580aba-a804-4afc-adb3-b8ce342c78f6/</guid><pubDate>Thu, 18 Sep 2025 00:00:00 GMT</pubDate><description>Driver can be used to load unsigned drivers</description></item><item><title>ksapi.sys</title><link>https://www.loldrivers.io/drivers/7f80bb6e-bbf6-46dd-b77d-ecef24f1c2cd/</link><guid>https://www.loldrivers.io/drivers/7f80bb6e-bbf6-46dd-b77d-ecef24f1c2cd/</guid><pubDate>Thu, 18 Sep 2025 00:00:00 GMT</pubDate><description>Driver can be used to load unsigned drivers</description></item><item><title>ksapi.sys</title><link>https://www.loldrivers.io/drivers/fb36ebc6-fdc5-42eb-929b-a07e00c5b9db/</link><guid>https://www.loldrivers.io/drivers/fb36ebc6-fdc5-42eb-929b-a07e00c5b9db/</guid><pubDate>Thu, 18 Sep 2025 00:00:00 GMT</pubDate><description>Driver can be used to load unsigned drivers</description></item><item><title>NSecKrnl.sys</title><link>https://www.loldrivers.io/drivers/c1143cd9-a709-4323-9678-2117285d1b47/</link><guid>https://www.loldrivers.io/drivers/c1143cd9-a709-4323-9678-2117285d1b47/</guid><pubDate>Thu, 18 Sep 2025 00:00:00 GMT</pubDate><description>Driver used by ValleyRAT malware to terminate security processes via IOCTL 0x2248E0</description></item><item><title>amsdk.sys</title><link>https://www.loldrivers.io/drivers/981210cb-8b84-4d37-b46e-b71059b8c438/</link><guid>https://www.loldrivers.io/drivers/981210cb-8b84-4d37-b46e-b71059b8c438/</guid><pubDate>Thu, 28 Aug 2025 00:00:00 GMT</pubDate><description>Vulnerable WatchDog Antimalware driver used by Silver Fox APT group to load unsigned drivers and execute malicious code in kernel mode</description></item><item><title>wamsdk.sys</title><link>https://www.loldrivers.io/drivers/9cb4b2fa-67fb-4415-a064-7da7bc47e105/</link><guid>https://www.loldrivers.io/drivers/9cb4b2fa-67fb-4415-a064-7da7bc47e105/</guid><pubDate>Thu, 28 Aug 2025 00:00:00 GMT</pubDate><description>Vulnerable WatchDog Antimalware driver used by Silver Fox APT group to load unsigned drivers and execute malicious code in kernel mode</description></item><item><title>927e3aef03a8355d236230cace376b3023480a40c5ac08453c07dab343dd1f11</title><link>https://www.loldrivers.io/drivers/9c4e45c8-8f99-40b4-bb73-2e1cfa813034/</link><guid>https://www.loldrivers.io/drivers/9c4e45c8-8f99-40b4-bb73-2e1cfa813034/</guid><pubDate>Fri, 08 Aug 2025 00:00:00 GMT</pubDate><description>According to Sophos X-Ops
(Aug 06, 2025), a widely shared EDR-killer toolkit drops/loads a malicious
kernel driver signed with compromised or revoked certificates to disable
endpoint protections. Variants target many vendors, and are commonly
HeartCrypt-packed and used by ransomware groups (e.g., RansomHub, INC).
The payload uses hard-coded driver names (e.g., mraml.sys, noedt.sys) and
kills security services/processes.</description></item><item><title>CSAgent.sys</title><link>https://www.loldrivers.io/drivers/8e673a36-4f16-4f4c-acf7-ca95bc586384/</link><guid>https://www.loldrivers.io/drivers/8e673a36-4f16-4f4c-acf7-ca95bc586384/</guid><pubDate>Fri, 08 Aug 2025 00:00:00 GMT</pubDate><description>Sophos X-Ops (Aug 06, 2025)
documents a shared EDR-killer technique where a user-mode loader deploys a
malicious kernel driver signed with compromised/revoked certificates (e.g.,
Changsha Hengxiang Information Technology; Fuzhou Dingxin Trade). The
driver terminates processes/services of multiple security vendors and is
often delivered packed with HeartCrypt during ransomware intrusions
(RansomHub, INC, others). Sample-specific driver names (e.g., mraml.sys,
noedt.sys) are hard-coded in the payload.</description></item><item><title>cyvrlpc.sys</title><link>https://www.loldrivers.io/drivers/85f8ad5b-c5aa-468b-99f3-4b0aacfaa724/</link><guid>https://www.loldrivers.io/drivers/85f8ad5b-c5aa-468b-99f3-4b0aacfaa724/</guid><pubDate>Fri, 08 Aug 2025 00:00:00 GMT</pubDate><description>Per Sophos X-Ops research
(Aug 06, 2025), threat actors deploy an EDR-killer that loads a malicious
kernel driver (often with a random five-letter name) signed with
compromised or revoked code-signing certificates (e.g., Changsha Hengxiang
Information Technology; Fuzhou Dingxin Trade). The tool targets many
security products by killing their services and processes and is frequently
distributed packed with HeartCrypt by ransomware groups (e.g., RansomHub,
INC). Driver names are hard-coded per sample (e.g., mraml.sys, noedt.sys).</description></item><item><title>throttlestop.sys</title><link>https://www.loldrivers.io/drivers/6e0786f5-2168-40a8-a068-e261c4eb10e7/</link><guid>https://www.loldrivers.io/drivers/6e0786f5-2168-40a8-a068-e261c4eb10e7/</guid><pubDate>Thu, 29 May 2025 00:00:00 GMT</pubDate><description>ThrottleStop is developed by TechPowerUp and is designed to monitor for and correct CPU throttling issues. However, Kaspersky researchers from the Global Emergency Response Team (GERT) found out that it is being abused by attackers to terminate defense mechanisms.</description></item><item><title>SmSerl64.sys</title><link>https://www.loldrivers.io/drivers/09c46890-5aa1-4122-962e-7ed94754e710/</link><guid>https://www.loldrivers.io/drivers/09c46890-5aa1-4122-962e-7ed94754e710/</guid><pubDate>Wed, 28 May 2025 00:00:00 GMT</pubDate><description>A vulnerability exits in driver SmSerl64.sys in Motorola SM56 Modem WDM Driver v6.12.23.0, which allows low-privileged users to mapping physical memory via specially crafted IOCTL requests . This can be exploited for privilege escalation, code execution under high privileges, and information disclosure. These signed drivers can also be used to bypass the Microsoft driver-signing policy to deploy malicious code.</description></item><item><title>8492937_2_Driver.sys</title><link>https://www.loldrivers.io/drivers/c95a796a-a8f6-4cfa-bc42-4936ecb59091/</link><guid>https://www.loldrivers.io/drivers/c95a796a-a8f6-4cfa-bc42-4936ecb59091/</guid><pubDate>Wed, 26 Mar 2025 00:00:00 GMT</pubDate><description>ABYSSWORKER is a malicious driver used in MEDUSA ransomware attacks to disable EDR systems. The driver masquerades as a legitimate CrowdStrike Falcon driver and provides extensive capabilities to terminate processes, remove security callbacks, manipulate files, and disable security tools. It uses stolen certificates from Chinese companies and requires a specific password for activation. The driver was observed being deployed alongside HEARTCRYPT-packed loaders and provides attackers with kernel-level capabilities to blind EDR products by removing notification callbacks, detaching mini-filter devices, and replacing driver major functions.</description></item><item><title>ACPIx86.sys</title><link>https://www.loldrivers.io/drivers/fd6c52b1-aeaa-4d89-8051-91acc68c3270/</link><guid>https://www.loldrivers.io/drivers/fd6c52b1-aeaa-4d89-8051-91acc68c3270/</guid><pubDate>Wed, 26 Mar 2025 00:00:00 GMT</pubDate><description>ABYSSWORKER is a malicious driver used in MEDUSA ransomware attacks to disable EDR systems. The driver masquerades as a legitimate CrowdStrike Falcon driver and provides extensive capabilities to terminate processes, remove security callbacks, manipulate files, and disable security tools. It uses stolen certificates from Chinese companies and requires a specific password for activation. The driver was observed being deployed alongside HEARTCRYPT-packed loaders and provides attackers with kernel-level capabilities to blind EDR products by removing notification callbacks, detaching mini-filter devices, and replacing driver major functions.</description></item><item><title>CSAgent.sys</title><link>https://www.loldrivers.io/drivers/9974b134-7fee-4c7a-9b0d-38b3b2d7e957/</link><guid>https://www.loldrivers.io/drivers/9974b134-7fee-4c7a-9b0d-38b3b2d7e957/</guid><pubDate>Wed, 26 Mar 2025 00:00:00 GMT</pubDate><description>ABYSSWORKER is a malicious driver used in MEDUSA ransomware attacks to disable EDR systems. The driver masquerades as a legitimate CrowdStrike Falcon driver and provides extensive capabilities to terminate processes, remove security callbacks, manipulate files, and disable security tools. It uses stolen certificates from Chinese companies and requires a specific password for activation. The driver was observed being deployed alongside HEARTCRYPT-packed loaders and provides attackers with kernel-level capabilities to blind EDR products by removing notification callbacks, detaching mini-filter devices, and replacing driver major functions.</description></item><item><title>CSAgent.sys</title><link>https://www.loldrivers.io/drivers/ca6455d1-b06e-496c-be33-f89c41b27540/</link><guid>https://www.loldrivers.io/drivers/ca6455d1-b06e-496c-be33-f89c41b27540/</guid><pubDate>Wed, 26 Mar 2025 00:00:00 GMT</pubDate><description>ABYSSWORKER is a malicious driver used in MEDUSA ransomware attacks to disable EDR systems. The driver masquerades as a legitimate CrowdStrike Falcon driver and provides extensive capabilities to terminate processes, remove security callbacks, manipulate files, and disable security tools. It uses stolen certificates from Chinese companies and requires a specific password for activation. The driver was observed being deployed alongside HEARTCRYPT-packed loaders and provides attackers with kernel-level capabilities to blind EDR products by removing notification callbacks, detaching mini-filter devices, and replacing driver major functions.</description></item><item><title>isodrivep64.sys</title><link>https://www.loldrivers.io/drivers/0144dbef-1da8-406c-8e35-7afee57dc471/</link><guid>https://www.loldrivers.io/drivers/0144dbef-1da8-406c-8e35-7afee57dc471/</guid><pubDate>Wed, 26 Mar 2025 00:00:00 GMT</pubDate><description>ABYSSWORKER is a malicious driver used in MEDUSA ransomware attacks to disable EDR systems. The driver masquerades as a legitimate CrowdStrike Falcon driver and provides extensive capabilities to terminate processes, remove security callbacks, manipulate files, and disable security tools. It uses stolen certificates from Chinese companies and requires a specific password for activation. The driver was observed being deployed alongside HEARTCRYPT-packed loaders and provides attackers with kernel-level capabilities to blind EDR products by removing notification callbacks, detaching mini-filter devices, and replacing driver major functions.</description></item><item><title>isodrivep64.sys</title><link>https://www.loldrivers.io/drivers/bd6490c2-20ea-441e-803c-bc3b957dae4c/</link><guid>https://www.loldrivers.io/drivers/bd6490c2-20ea-441e-803c-bc3b957dae4c/</guid><pubDate>Wed, 26 Mar 2025 00:00:00 GMT</pubDate><description>ABYSSWORKER is a malicious driver used in MEDUSA ransomware attacks to disable EDR systems. The driver masquerades as a legitimate CrowdStrike Falcon driver and provides extensive capabilities to terminate processes, remove security callbacks, manipulate files, and disable security tools. It uses stolen certificates from Chinese companies and requires a specific password for activation. The driver was observed being deployed alongside HEARTCRYPT-packed loaders and provides attackers with kernel-level capabilities to blind EDR products by removing notification callbacks, detaching mini-filter devices, and replacing driver major functions.</description></item><item><title>vsdatant.sys</title><link>https://www.loldrivers.io/drivers/87d5ec39-482e-4e78-a003-be4b662f85fc/</link><guid>https://www.loldrivers.io/drivers/87d5ec39-482e-4e78-a003-be4b662f85fc/</guid><pubDate>Sat, 22 Mar 2025 00:00:00 GMT</pubDate><description>Check Point ZoneAlarm driver (vsdatant.sys) abused in BYOVD attacks to gain kernel privileges and bypass protections such as Memory Integrity.</description></item><item><title>BioNTdrv.sys</title><link>https://www.loldrivers.io/drivers/e6378671-986d-42a1-8e7a-717117c83751/</link><guid>https://www.loldrivers.io/drivers/e6378671-986d-42a1-8e7a-717117c83751/</guid><pubDate>Sun, 02 Mar 2025 00:00:00 GMT</pubDate><description>Paragon Hard Disk Manager BioNTdrv.sys versions 10.1.x and older, 1.0.0.0, 1.1.0.0, 1.3.0.0, 1.4.0.0, and 1.5.1.0 contain five vulnerabilities that expose arbitrary kernel-memory mapping, write, and move operations, insecure kernel resource access, and a null-pointer dereference. Local attackers can use the affected driver to elevate to SYSTEM or cause a denial of service. CVE-2025-0289 has been observed in ransomware BYOVD attacks. Version 2.0.0 fixes the flaws.</description></item><item><title>TPwSav.sys</title><link>https://www.loldrivers.io/drivers/c0634ed7-840e-4a7e-8b34-33efe50405c2/</link><guid>https://www.loldrivers.io/drivers/c0634ed7-840e-4a7e-8b34-33efe50405c2/</guid><pubDate>Fri, 31 Jan 2025 00:00:00 GMT</pubDate><description>A driver associated with Toshiba laptops power saving functionality allows arbitary one byte reading and writing mapped physical addresses. Blackpoint Cyber&apos;s SOC observed this driver being used as part of a custom EDRSandblast malware to blind EDR prior to Qilin ransomware deployment.</description></item><item><title>probmon.sys</title><link>https://www.loldrivers.io/drivers/3bf3fd5d-dee3-42da-b8be-6a0b8b7bc88c/</link><guid>https://www.loldrivers.io/drivers/3bf3fd5d-dee3-42da-b8be-6a0b8b7bc88c/</guid><pubDate>Wed, 29 Jan 2025 00:00:00 GMT</pubDate><description>A vulnerable kernel driver that can be used to terminate arbitrary processes</description></item><item><title>dellinstrumentation.sys</title><link>https://www.loldrivers.io/drivers/86b9c8d6-9c59-4fd4-befd-ab9a36a19e36/</link><guid>https://www.loldrivers.io/drivers/86b9c8d6-9c59-4fd4-befd-ab9a36a19e36/</guid><pubDate>Mon, 13 Jan 2025 00:00:00 GMT</pubDate><description></description></item><item><title>szkg64.sys</title><link>https://www.loldrivers.io/drivers/375e8de3-aae4-488d-8273-66744978b45f/</link><guid>https://www.loldrivers.io/drivers/375e8de3-aae4-488d-8273-66744978b45f/</guid><pubDate>Fri, 10 Jan 2025 00:00:00 GMT</pubDate><description>The StopZilla driver is a forgotten but still exploitable vulnerable driver that allows arbitrary kernel memory writes via unvalidated IOCTLs (0x80002063 and 0x8000206F). Attackers can leverage it to escalate privileges, disable LSASS PPL protection, and even modify PreviousMode in _KTHREAD to execute user-mode code as kernel-mode, effectively bypassing security checks. Despite its risks, it remains unblocked by Microsoft’s Driver Block List and many AV/EDR solutions. This driver highlights the persistent threat of forgotten vulnerable drivers still exploitable in modern Windows environments.</description></item><item><title>AccelLid.sys</title><link>https://www.loldrivers.io/drivers/d9e9fab2-6b64-4c14-b1ec-7af1923c0773/</link><guid>https://www.loldrivers.io/drivers/d9e9fab2-6b64-4c14-b1ec-7af1923c0773/</guid><pubDate>Wed, 11 Sep 2024 00:00:00 GMT</pubDate><description>AccelLid.sys is an Elitegroup Computer Systems lid accelerometer kernel driver. Northwave Cyber Security reported a local denial-of-service vulnerability with a CVSSv3 score of 5.5. The driver exposes IOCTL paths for accelerometer commands, keyboard control, event registration, and ACPI method execution. Microsoft&apos;s vulnerable driver blocklist denies AccelLid.sys across all file versions for matching Elitegroup publisher and signing roots.</description></item><item><title>ADRMDRVSYS.sys</title><link>https://www.loldrivers.io/drivers/48aeea9b-7812-4b25-9835-baaebe7dc551/</link><guid>https://www.loldrivers.io/drivers/48aeea9b-7812-4b25-9835-baaebe7dc551/</guid><pubDate>Wed, 11 Sep 2024 00:00:00 GMT</pubDate><description>ADLINK Resource Manager exposes physical-memory mapping through IOCTL 0x2234D4, allowing low-privilege callers to read kernel memory. The interface has also been weaponized by Blackout Reloaded to terminate protected antimalware processes through a driver path that reaches ZwTerminateProcess.</description></item><item><title>ampa.sys</title><link>https://www.loldrivers.io/drivers/ea0e7351-b65c-4c5a-9863-83b9d5efcec3/</link><guid>https://www.loldrivers.io/drivers/ea0e7351-b65c-4c5a-9863-83b9d5efcec3/</guid><pubDate>Wed, 11 Sep 2024 00:00:00 GMT</pubDate><description>Northwave Cyber Security contributed this driver based on in-house research. The driver has a CVSSv3 score of 8.8, indicating a privilege escalation impact. This vulnerability could potentially be exploited for privilege escalation or other malicious activities.</description></item><item><title>hw.sys</title><link>https://www.loldrivers.io/drivers/5076e737-6744-4266-bef7-bceda65050d6/</link><guid>https://www.loldrivers.io/drivers/5076e737-6744-4266-bef7-bceda65050d6/</guid><pubDate>Wed, 11 Sep 2024 00:00:00 GMT</pubDate><description>Northwave Cyber Security contributed this driver based on in-house research. The driver has a CVSSv3 score of 8.8, indicating a privilege escalation impact. This vulnerability could potentially be exploited for privilege escalation or other malicious activities.</description></item><item><title>jnprva.sys</title><link>https://www.loldrivers.io/drivers/c44e6197-efab-49d2-8a5f-04ae4a0f0ea0/</link><guid>https://www.loldrivers.io/drivers/c44e6197-efab-49d2-8a5f-04ae4a0f0ea0/</guid><pubDate>Wed, 11 Sep 2024 00:00:00 GMT</pubDate><description>Northwave Cyber Security contributed this driver based on in-house research. The driver has a CVSSv3 score of 8.8, indicating a privilege escalation impact. This vulnerability could potentially be exploited for privilege escalation or other malicious activities.</description></item><item><title>ProcObsrvesx.sys</title><link>https://www.loldrivers.io/drivers/8a1a4a5d-3e41-4539-80cd-0cb751f7fab3/</link><guid>https://www.loldrivers.io/drivers/8a1a4a5d-3e41-4539-80cd-0cb751f7fab3/</guid><pubDate>Wed, 11 Sep 2024 00:00:00 GMT</pubDate><description>Northwave Cyber Security contributed this driver based on in-house research. The driver has a CVSSv3 score of 8.8, indicating a privilege escalation impact. This vulnerability could potentially be exploited for privilege escalation or other malicious activities.</description></item><item><title>psmounterex.sys</title><link>https://www.loldrivers.io/drivers/0f64bf7a-2ef2-45ea-af7d-4e7c87d98777/</link><guid>https://www.loldrivers.io/drivers/0f64bf7a-2ef2-45ea-af7d-4e7c87d98777/</guid><pubDate>Wed, 11 Sep 2024 00:00:00 GMT</pubDate><description>Northwave Cyber Security contributed this driver based on in-house research. The driver has a CVSSv3 score of 8.8, indicating a privelege escalation impact. This vulnerability could potentially be exploited for privilege escalation or other malicious activities.</description></item><item><title>pxitrig64.sys</title><link>https://www.loldrivers.io/drivers/c8619f49-8e23-489b-9878-53d27533da15/</link><guid>https://www.loldrivers.io/drivers/c8619f49-8e23-489b-9878-53d27533da15/</guid><pubDate>Wed, 11 Sep 2024 00:00:00 GMT</pubDate><description>Northwave Cyber Security contributed this driver based on in-house research. The driver has a CVSSv3 score of 5.5, indicating a local dos impact. This vulnerability could potentially be exploited for privilege escalation or other malicious activities.</description></item><item><title>SeasunProtect.sys</title><link>https://www.loldrivers.io/drivers/3a9ea9a6-e5e3-439a-b892-1f78dd990099/</link><guid>https://www.loldrivers.io/drivers/3a9ea9a6-e5e3-439a-b892-1f78dd990099/</guid><pubDate>Wed, 11 Sep 2024 00:00:00 GMT</pubDate><description>Northwave Cyber Security contributed this driver based on in-house research. The driver has a CVSSv3 score of 8.8, indicating a privilege escalation impact. This vulnerability could potentially be exploited for privilege escalation or other malicious activities.</description></item><item><title>tboflhelper.sys</title><link>https://www.loldrivers.io/drivers/07c57c69-c8d7-40cf-8bcc-612671427044/</link><guid>https://www.loldrivers.io/drivers/07c57c69-c8d7-40cf-8bcc-612671427044/</guid><pubDate>Wed, 11 Sep 2024 00:00:00 GMT</pubDate><description>Northwave Cyber Security contributed this driver based on in-house research. The driver has a CVSSv3 score of 8.8, indicating a privelege escalation impact. This vulnerability could potentially be exploited for privilege escalation or other malicious activities.</description></item><item><title>TSDRVX64.sys</title><link>https://www.loldrivers.io/drivers/424a387e-735e-49d1-99de-f067dcf1c3e9/</link><guid>https://www.loldrivers.io/drivers/424a387e-735e-49d1-99de-f067dcf1c3e9/</guid><pubDate>Wed, 11 Sep 2024 00:00:00 GMT</pubDate><description>Northwave Cyber Security identified TSDRVX64 as a local privilege-escalation vulnerability with a CVSSv3 score of 8.8. Successful exploitation provides kernel-level impact and may enable an attacker to disable security controls or tamper with the operating system.</description></item><item><title>ViveRRAudio.sys</title><link>https://www.loldrivers.io/drivers/4cb95b41-43b4-4806-b536-ae5fd8c76b0e/</link><guid>https://www.loldrivers.io/drivers/4cb95b41-43b4-4806-b536-ae5fd8c76b0e/</guid><pubDate>Wed, 11 Sep 2024 00:00:00 GMT</pubDate><description>Northwave Cyber Security contributed this driver based on in-house research. The driver has a CVSSv3 score of 5.5, indicating a information disclosure / local dos impact. This vulnerability could potentially be exploited for privilege escalation or other malicious activities.</description></item><item><title>wsftprm.sys</title><link>https://www.loldrivers.io/drivers/30e8d598-2c60-49e4-953b-a6f620da1371/</link><guid>https://www.loldrivers.io/drivers/30e8d598-2c60-49e4-953b-a6f620da1371/</guid><pubDate>Wed, 11 Sep 2024 00:00:00 GMT</pubDate><description>Northwave Cyber Security contributed this driver based on in-house research. The driver has a CVSSv3 score of 6.1, indicating a antivirus killer impact. This vulnerability could potentially be exploited for privilege escalation or other malicious activities.</description></item><item><title>2.sys</title><link>https://www.loldrivers.io/drivers/bb1f80f3-d2fd-463e-9403-57c919bd976b/</link><guid>https://www.loldrivers.io/drivers/bb1f80f3-d2fd-463e-9403-57c919bd976b/</guid><pubDate>Tue, 10 Sep 2024 00:00:00 GMT</pubDate><description>Sophos, from time to time, has observed a threat actor deploy variants of Poortry on different machines within a single estate during an attack. These variants contain the same payload, but signed with a different certificate than the driver first seen used during the attack.</description></item><item><title>avkiller.sys</title><link>https://www.loldrivers.io/drivers/7a9d34e4-c660-4388-ab61-4fd6f6bf1ad4/</link><guid>https://www.loldrivers.io/drivers/7a9d34e4-c660-4388-ab61-4fd6f6bf1ad4/</guid><pubDate>Tue, 10 Sep 2024 00:00:00 GMT</pubDate><description>Sophos, from time to time, has observed a threat actor deploy variants
    of Poortry on different machines within a single estate during an attack. These
    variants contain the same payload, but signed with a different certificate than
    the driver first seen used during the attack.</description></item><item><title>driver_090d409f.sys</title><link>https://www.loldrivers.io/drivers/00561455-9da1-4f0c-8564-e4c99b716a74/</link><guid>https://www.loldrivers.io/drivers/00561455-9da1-4f0c-8564-e4c99b716a74/</guid><pubDate>Tue, 10 Sep 2024 00:00:00 GMT</pubDate><description>Sophos, from time to time, has observed a threat actor deploy variants of Poortry on different machines within a single estate during an attack. These variants contain the same payload, but signed with a different certificate than the driver first seen used during the attack.</description></item><item><title>driver_099ef491.sys</title><link>https://www.loldrivers.io/drivers/2ba1bccf-d8d7-464a-9ae1-41371c55e5e8/</link><guid>https://www.loldrivers.io/drivers/2ba1bccf-d8d7-464a-9ae1-41371c55e5e8/</guid><pubDate>Tue, 10 Sep 2024 00:00:00 GMT</pubDate><description>Sophos, from time to time, has observed a threat actor deploy variants of Poortry on different machines within a single estate during an attack. These variants contain the same payload, but signed with a different certificate than the driver first seen used during the attack.</description></item><item><title>driver_0a636606.sys</title><link>https://www.loldrivers.io/drivers/82087b26-b649-4ad1-a353-3a225c757ff7/</link><guid>https://www.loldrivers.io/drivers/82087b26-b649-4ad1-a353-3a225c757ff7/</guid><pubDate>Tue, 10 Sep 2024 00:00:00 GMT</pubDate><description>Sophos, from time to time, has observed a threat actor deploy variants of Poortry on different machines within a single estate during an attack. These variants contain the same payload, but signed with a different certificate than the driver first seen used during the attack.</description></item><item><title>driver_0ffb4081.sys</title><link>https://www.loldrivers.io/drivers/8081b0d0-e18e-474a-bdfa-8ff1956d90cb/</link><guid>https://www.loldrivers.io/drivers/8081b0d0-e18e-474a-bdfa-8ff1956d90cb/</guid><pubDate>Tue, 10 Sep 2024 00:00:00 GMT</pubDate><description>Sophos, from time to time, has observed a threat actor deploy variants of Poortry on different machines within a single estate during an attack. These variants contain the same payload, but signed with a different certificate than the driver first seen used during the attack.</description></item><item><title>driver_146b8f4f.sys</title><link>https://www.loldrivers.io/drivers/cea8bd08-a3c5-4ae1-a568-387b909ada67/</link><guid>https://www.loldrivers.io/drivers/cea8bd08-a3c5-4ae1-a568-387b909ada67/</guid><pubDate>Tue, 10 Sep 2024 00:00:00 GMT</pubDate><description>Sophos, from time to time, has observed a threat actor deploy variants of Poortry on different machines within a single estate during an attack. These variants contain the same payload, but signed with a different certificate than the driver first seen used during the attack.</description></item><item><title>driver_16773074.sys</title><link>https://www.loldrivers.io/drivers/a0f0d0db-15a2-48e4-af39-50967ee8b541/</link><guid>https://www.loldrivers.io/drivers/a0f0d0db-15a2-48e4-af39-50967ee8b541/</guid><pubDate>Tue, 10 Sep 2024 00:00:00 GMT</pubDate><description>Sophos, from time to time, has observed a threat actor deploy variants of Poortry on different machines within a single estate during an attack. These variants contain the same payload, but signed with a different certificate than the driver first seen used during the attack.</description></item><item><title>driver_1a74c2bd.sys</title><link>https://www.loldrivers.io/drivers/af153e7c-13fa-4a40-a095-00726ad6d783/</link><guid>https://www.loldrivers.io/drivers/af153e7c-13fa-4a40-a095-00726ad6d783/</guid><pubDate>Tue, 10 Sep 2024 00:00:00 GMT</pubDate><description>Sophos, from time to time, has observed a threat actor deploy variants of Poortry on different machines within a single estate during an attack. These variants contain the same payload, but signed with a different certificate than the driver first seen used during the attack.</description></item><item><title>driver_1afc1d06.sys</title><link>https://www.loldrivers.io/drivers/d7773616-9860-4768-b6a2-d74f32c23b4e/</link><guid>https://www.loldrivers.io/drivers/d7773616-9860-4768-b6a2-d74f32c23b4e/</guid><pubDate>Tue, 10 Sep 2024 00:00:00 GMT</pubDate><description>Sophos, from time to time, has observed a threat actor deploy variants of Poortry on different machines within a single estate during an attack. These variants contain the same payload, but signed with a different certificate than the driver first seen used during the attack.</description></item><item><title>driver_206006a1.sys</title><link>https://www.loldrivers.io/drivers/9e0a1bae-6509-41fd-a5bf-dfe6cf388682/</link><guid>https://www.loldrivers.io/drivers/9e0a1bae-6509-41fd-a5bf-dfe6cf388682/</guid><pubDate>Tue, 10 Sep 2024 00:00:00 GMT</pubDate><description>Sophos, from time to time, has observed a threat actor deploy variants of Poortry on different machines within a single estate during an attack. These variants contain the same payload, but signed with a different certificate than the driver first seen used during the attack.</description></item><item><title>driver_290bc782.sys</title><link>https://www.loldrivers.io/drivers/f5c1a46f-21e6-4b06-b212-2dc55b699497/</link><guid>https://www.loldrivers.io/drivers/f5c1a46f-21e6-4b06-b212-2dc55b699497/</guid><pubDate>Tue, 10 Sep 2024 00:00:00 GMT</pubDate><description>Sophos, from time to time, has observed a threat actor deploy variants of Poortry on different machines within a single estate during an attack. These variants contain the same payload, but signed with a different certificate than the driver first seen used during the attack.</description></item><item><title>driver_312c83a9.sys</title><link>https://www.loldrivers.io/drivers/495f0f36-c5e0-467d-8115-b5bdbe7ff686/</link><guid>https://www.loldrivers.io/drivers/495f0f36-c5e0-467d-8115-b5bdbe7ff686/</guid><pubDate>Tue, 10 Sep 2024 00:00:00 GMT</pubDate><description>Sophos, from time to time, has observed a threat actor deploy variants of Poortry on different machines within a single estate during an attack. These variants contain the same payload, but signed with a different certificate than the driver first seen used during the attack.</description></item><item><title>driver_4d8bc539.sys</title><link>https://www.loldrivers.io/drivers/e7fd8ffc-ab37-4a7b-8dc9-fc7432fbacae/</link><guid>https://www.loldrivers.io/drivers/e7fd8ffc-ab37-4a7b-8dc9-fc7432fbacae/</guid><pubDate>Tue, 10 Sep 2024 00:00:00 GMT</pubDate><description>Sophos, from time to time, has observed a threat actor deploy variants of Poortry on different machines within a single estate during an attack. These variants contain the same payload, but signed with a different certificate than the driver first seen used during the attack.</description></item><item><title>driver_4f9b5a2f.sys</title><link>https://www.loldrivers.io/drivers/b660d253-2b60-46c5-b95a-c354aa5eb154/</link><guid>https://www.loldrivers.io/drivers/b660d253-2b60-46c5-b95a-c354aa5eb154/</guid><pubDate>Tue, 10 Sep 2024 00:00:00 GMT</pubDate><description>Sophos, from time to time, has observed a threat actor deploy variants of Poortry on different machines within a single estate during an attack. These variants contain the same payload, but signed with a different certificate than the driver first seen used during the attack.</description></item><item><title>driver_4fc254af.sys</title><link>https://www.loldrivers.io/drivers/85335187-dae0-4f06-acea-209efaf74973/</link><guid>https://www.loldrivers.io/drivers/85335187-dae0-4f06-acea-209efaf74973/</guid><pubDate>Tue, 10 Sep 2024 00:00:00 GMT</pubDate><description>Sophos, from time to time, has observed a threat actor deploy variants of Poortry on different machines within a single estate during an attack. These variants contain the same payload, but signed with a different certificate than the driver first seen used during the attack.</description></item><item><title>driver_5c308aed.sys</title><link>https://www.loldrivers.io/drivers/647f72e7-f378-4908-946c-5e45fab448e8/</link><guid>https://www.loldrivers.io/drivers/647f72e7-f378-4908-946c-5e45fab448e8/</guid><pubDate>Tue, 10 Sep 2024 00:00:00 GMT</pubDate><description>Sophos, from time to time, has observed a threat actor deploy variants of Poortry on different machines within a single estate during an attack. These variants contain the same payload, but signed with a different certificate than the driver first seen used during the attack.</description></item><item><title>driver_5d61e4ea.sys</title><link>https://www.loldrivers.io/drivers/0215d6d6-e0c4-4a11-bd3a-40511f89d736/</link><guid>https://www.loldrivers.io/drivers/0215d6d6-e0c4-4a11-bd3a-40511f89d736/</guid><pubDate>Tue, 10 Sep 2024 00:00:00 GMT</pubDate><description>Sophos, from time to time, has observed a threat actor deploy variants of Poortry on different machines within a single estate during an attack. These variants contain the same payload, but signed with a different certificate than the driver first seen used during the attack.</description></item><item><title>driver_668c5bea.sys</title><link>https://www.loldrivers.io/drivers/04eefdf4-448d-45bb-87fc-93f263fc77f4/</link><guid>https://www.loldrivers.io/drivers/04eefdf4-448d-45bb-87fc-93f263fc77f4/</guid><pubDate>Tue, 10 Sep 2024 00:00:00 GMT</pubDate><description>Sophos, from time to time, has observed a threat actor deploy variants of Poortry on different machines within a single estate during an attack. These variants contain the same payload, but signed with a different certificate than the driver first seen used during the attack.</description></item><item><title>driver_77225a99.sys</title><link>https://www.loldrivers.io/drivers/5fb86651-c152-404a-9a2f-0f54b0d2bb55/</link><guid>https://www.loldrivers.io/drivers/5fb86651-c152-404a-9a2f-0f54b0d2bb55/</guid><pubDate>Tue, 10 Sep 2024 00:00:00 GMT</pubDate><description>Sophos, from time to time, has observed a threat actor deploy variants of Poortry on different machines within a single estate during an attack. These variants contain the same payload, but signed with a different certificate than the driver first seen used during the attack.</description></item><item><title>driver_82d928c5.sys</title><link>https://www.loldrivers.io/drivers/af8ef3c0-8686-4112-992b-86587a4a9060/</link><guid>https://www.loldrivers.io/drivers/af8ef3c0-8686-4112-992b-86587a4a9060/</guid><pubDate>Tue, 10 Sep 2024 00:00:00 GMT</pubDate><description>Sophos, from time to time, has observed a threat actor deploy variants of Poortry on different machines within a single estate during an attack. These variants contain the same payload, but signed with a different certificate than the driver first seen used during the attack.</description></item><item><title>driver_85ca0dcd.sys</title><link>https://www.loldrivers.io/drivers/e1c29414-5b5b-44f4-84cc-e6f55d9a23c6/</link><guid>https://www.loldrivers.io/drivers/e1c29414-5b5b-44f4-84cc-e6f55d9a23c6/</guid><pubDate>Tue, 10 Sep 2024 00:00:00 GMT</pubDate><description>Sophos, from time to time, has observed a threat actor deploy variants of Poortry on different machines within a single estate during an attack. These variants contain the same payload, but signed with a different certificate than the driver first seen used during the attack.</description></item><item><title>driver_89036534.sys</title><link>https://www.loldrivers.io/drivers/750a8aa9-a87c-4142-b96b-18ea139ada14/</link><guid>https://www.loldrivers.io/drivers/750a8aa9-a87c-4142-b96b-18ea139ada14/</guid><pubDate>Tue, 10 Sep 2024 00:00:00 GMT</pubDate><description>Sophos, from time to time, has observed a threat actor deploy variants of Poortry on different machines within a single estate during an attack. These variants contain the same payload, but signed with a different certificate than the driver first seen used during the attack.</description></item><item><title>driver_930da474.sys</title><link>https://www.loldrivers.io/drivers/4c4e7664-af86-4483-858a-f59346f3d304/</link><guid>https://www.loldrivers.io/drivers/4c4e7664-af86-4483-858a-f59346f3d304/</guid><pubDate>Tue, 10 Sep 2024 00:00:00 GMT</pubDate><description>Sophos, from time to time, has observed a threat actor deploy variants of Poortry on different machines within a single estate during an attack. These variants contain the same payload, but signed with a different certificate than the driver first seen used during the attack.</description></item><item><title>driver_981d03e1.sys</title><link>https://www.loldrivers.io/drivers/1106fe7a-b78b-4edf-85c0-6208979f380b/</link><guid>https://www.loldrivers.io/drivers/1106fe7a-b78b-4edf-85c0-6208979f380b/</guid><pubDate>Tue, 10 Sep 2024 00:00:00 GMT</pubDate><description>Sophos, from time to time, has observed a threat actor deploy variants of Poortry on different machines within a single estate during an attack. These variants contain the same payload, but signed with a different certificate than the driver first seen used during the attack.</description></item><item><title>driver_a6deeea6.sys</title><link>https://www.loldrivers.io/drivers/f694c0e1-b75d-4c41-acbd-a87b72d8abe4/</link><guid>https://www.loldrivers.io/drivers/f694c0e1-b75d-4c41-acbd-a87b72d8abe4/</guid><pubDate>Tue, 10 Sep 2024 00:00:00 GMT</pubDate><description>Sophos, from time to time, has observed a threat actor deploy variants of Poortry on different machines within a single estate during an attack. These variants contain the same payload, but signed with a different certificate than the driver first seen used during the attack.</description></item><item><title>driver_ab811ca5.sys</title><link>https://www.loldrivers.io/drivers/09d2e61d-e041-4ec8-ab7b-385848456a36/</link><guid>https://www.loldrivers.io/drivers/09d2e61d-e041-4ec8-ab7b-385848456a36/</guid><pubDate>Tue, 10 Sep 2024 00:00:00 GMT</pubDate><description>Sophos, from time to time, has observed a threat actor deploy variants of Poortry on different machines within a single estate during an attack. These variants contain the same payload, but signed with a different certificate than the driver first seen used during the attack.</description></item><item><title>driver_b4f33ffe.sys</title><link>https://www.loldrivers.io/drivers/51a44484-8bcc-4150-8b94-4a755cff0af8/</link><guid>https://www.loldrivers.io/drivers/51a44484-8bcc-4150-8b94-4a755cff0af8/</guid><pubDate>Tue, 10 Sep 2024 00:00:00 GMT</pubDate><description>Sophos, from time to time, has observed a threat actor deploy variants of Poortry on different machines within a single estate during an attack. These variants contain the same payload, but signed with a different certificate than the driver first seen used during the attack.</description></item><item><title>driver_bfcbc010.sys</title><link>https://www.loldrivers.io/drivers/dbfcce10-76a3-44a4-a9b8-d7126152a235/</link><guid>https://www.loldrivers.io/drivers/dbfcce10-76a3-44a4-a9b8-d7126152a235/</guid><pubDate>Tue, 10 Sep 2024 00:00:00 GMT</pubDate><description>Sophos, from time to time, has observed a threat actor deploy variants of Poortry on different machines within a single estate during an attack. These variants contain the same payload, but signed with a different certificate than the driver first seen used during the attack.</description></item><item><title>driver_c3d48ddd.sys</title><link>https://www.loldrivers.io/drivers/f6c08b8a-1d25-4bf1-9d4f-5368c1f6cfe7/</link><guid>https://www.loldrivers.io/drivers/f6c08b8a-1d25-4bf1-9d4f-5368c1f6cfe7/</guid><pubDate>Tue, 10 Sep 2024 00:00:00 GMT</pubDate><description>Sophos, from time to time, has observed a threat actor deploy variants of Poortry on different machines within a single estate during an attack. These variants contain the same payload, but signed with a different certificate than the driver first seen used during the attack.</description></item><item><title>driver_d1ea9e16.sys</title><link>https://www.loldrivers.io/drivers/8697785a-d088-42a7-ac25-b5c8a3b22664/</link><guid>https://www.loldrivers.io/drivers/8697785a-d088-42a7-ac25-b5c8a3b22664/</guid><pubDate>Tue, 10 Sep 2024 00:00:00 GMT</pubDate><description>Sophos, from time to time, has observed a threat actor deploy variants of Poortry on different machines within a single estate during an attack. These variants contain the same payload, but signed with a different certificate than the driver first seen used during the attack.</description></item><item><title>driver_d9f15d91.sys</title><link>https://www.loldrivers.io/drivers/576bb95a-f15e-4a0d-bcee-08791e1504e2/</link><guid>https://www.loldrivers.io/drivers/576bb95a-f15e-4a0d-bcee-08791e1504e2/</guid><pubDate>Tue, 10 Sep 2024 00:00:00 GMT</pubDate><description>Sophos, from time to time, has observed a threat actor deploy variants of Poortry on different machines within a single estate during an attack. These variants contain the same payload, but signed with a different certificate than the driver first seen used during the attack.</description></item><item><title>driver_e1123b59.sys</title><link>https://www.loldrivers.io/drivers/11a73c42-26aa-446b-8560-43eecb265091/</link><guid>https://www.loldrivers.io/drivers/11a73c42-26aa-446b-8560-43eecb265091/</guid><pubDate>Tue, 10 Sep 2024 00:00:00 GMT</pubDate><description>Sophos, from time to time, has observed a threat actor deploy variants of Poortry on different machines within a single estate during an attack. These variants contain the same payload, but signed with a different certificate than the driver first seen used during the attack.</description></item><item><title>driver_ef9d653a.sys</title><link>https://www.loldrivers.io/drivers/14e51012-5429-483e-9423-49778c3bd1c2/</link><guid>https://www.loldrivers.io/drivers/14e51012-5429-483e-9423-49778c3bd1c2/</guid><pubDate>Tue, 10 Sep 2024 00:00:00 GMT</pubDate><description>Sophos, from time to time, has observed a threat actor deploy variants of Poortry on different machines within a single estate during an attack. These variants contain the same payload, but signed with a different certificate than the driver first seen used during the attack.</description></item><item><title>driver_fdd16a94.sys</title><link>https://www.loldrivers.io/drivers/da066835-f37c-40bf-86bb-d77ad45c7f30/</link><guid>https://www.loldrivers.io/drivers/da066835-f37c-40bf-86bb-d77ad45c7f30/</guid><pubDate>Tue, 10 Sep 2024 00:00:00 GMT</pubDate><description>Sophos, from time to time, has observed a threat actor deploy variants of Poortry on different machines within a single estate during an attack. These variants contain the same payload, but signed with a different certificate than the driver first seen used during the attack.</description></item><item><title>f.sys</title><link>https://www.loldrivers.io/drivers/17a1ad58-ecf3-4dea-b1ca-336880d15256/</link><guid>https://www.loldrivers.io/drivers/17a1ad58-ecf3-4dea-b1ca-336880d15256/</guid><pubDate>Tue, 10 Sep 2024 00:00:00 GMT</pubDate><description>Sophos, from time to time, has observed a threat actor deploy variants
    of Poortry on different machines within a single estate during an attack. These
    variants contain the same payload, but signed with a different certificate than
    the driver first seen used during the attack.</description></item><item><title>RtsPer.sys</title><link>https://www.loldrivers.io/drivers/32155681-33e8-4d0d-b9f6-c822851e7321/</link><guid>https://www.loldrivers.io/drivers/32155681-33e8-4d0d-b9f6-c822851e7321/</guid><pubDate>Tue, 10 Sep 2024 00:00:00 GMT</pubDate><description>The Realtek SD card reader driver, RtsPer.sys, has been found to contain multiple critical vulnerabilities (CVE-2022-25476, CVE-2022-25477, CVE-2022-25478, CVE-2022-25479, CVE-2022-25480, CVE-2024-40431, CVE-2024-40432) that allow non-privileged users to leak kernel memory, write to arbitrary kernel memory, and access physical memory via DMA. These flaws affect various SD card reader models (including RTS5227, RTS5228, RTS522A, RTS5249, RTS524A, RTS5250, RTS525A, RTS5287, RTS5260, RTS5261, RTS5264) used by major OEMs such as Dell, Lenovo, HP, and MSI. The vulnerabilities enable kernel memory leaks, arbitrary kernel memory writes, PCI configuration space manipulation, and DMA controller access from user mode. Due to the driver&apos;s widespread use, the impact is significant, potentially allowing privilege escalation and system compromise. Realtek has addressed these issues in driver version 10.0.26100.21374 or higher, released in July or August.</description></item><item><title>RtsUer.sys</title><link>https://www.loldrivers.io/drivers/71d930a7-3465-4d27-90d4-2a1a08bebb92/</link><guid>https://www.loldrivers.io/drivers/71d930a7-3465-4d27-90d4-2a1a08bebb92/</guid><pubDate>Tue, 10 Sep 2024 00:00:00 GMT</pubDate><description>The Realtek SD card reader driver, RtsUer.sys, versions below or equal to 10.0.22000.31273 contain multiple vulnerabilities that pose significant security risks. These flaws allow non-privileged users to write to kernel memory and access the DMA controller from unprivileged accounts, potentially enabling privilege escalation and system compromise. The most severe issues include the ability to write to kernel memory and access the DMA controller, which could lead to unauthorized system modifications. These vulnerabilities affect various Realtek SD card reader models used by major OEM laptop manufacturers. Due to the widespread use of this driver, the impact is considerable, potentially affecting a large number of systems across different brands. Users with laptops equipped with Realtek SD card readers should ensure their drivers are updated to a version higher than 10.0.22000.31273 to mitigate these security risks.</description></item><item><title>windivert.sys</title><link>https://www.loldrivers.io/drivers/45a31a17-f78d-48ec-beba-74f6bfc5f96e/</link><guid>https://www.loldrivers.io/drivers/45a31a17-f78d-48ec-beba-74f6bfc5f96e/</guid><pubDate>Tue, 10 Sep 2024 00:00:00 GMT</pubDate><description>WinDivert is a user-mode packet capture and network packet manipulation utility designed for Windows. It provides a powerful and flexible framework for intercepting, modifying, injecting, and dropping network packets at the network stack level. It operates as a lightweight, high-performance driver that interfaces directly with the network stack, allowing for detailed packet inspection and manipulation in real time.</description></item><item><title>idmtdi.sys</title><link>https://www.loldrivers.io/drivers/c2e98102-2055-48f0-9449-3e7a7f2c0ffe/</link><guid>https://www.loldrivers.io/drivers/c2e98102-2055-48f0-9449-3e7a7f2c0ffe/</guid><pubDate>Wed, 28 Aug 2024 00:00:00 GMT</pubDate><description>Sophos, from time to time, has observed a threat actor deploy variants of Poortry on different machines within a single estate during an attack. These variants contain the same payload, but signed with a different certificate than the driver first seen used during the attack.</description></item><item><title>Afd.sys</title><link>https://www.loldrivers.io/drivers/394f49b2-2d78-4d0d-b374-1399695455f3/</link><guid>https://www.loldrivers.io/drivers/394f49b2-2d78-4d0d-b374-1399695455f3/</guid><pubDate>Wed, 21 Aug 2024 00:00:00 GMT</pubDate><description>Windows Ancillary Function Driver (Afd.sys) for WinSock is vulnerable to an Elevation of Privilege Vulnerability.</description></item><item><title>CSC.sys</title><link>https://www.loldrivers.io/drivers/1c92e1bf-103b-4545-b242-e5a9858ec9c8/</link><guid>https://www.loldrivers.io/drivers/1c92e1bf-103b-4545-b242-e5a9858ec9c8/</guid><pubDate>Wed, 21 Aug 2024 00:00:00 GMT</pubDate><description>Improper Address Validation in IOCTL with METHOD_NEITHER I/O Control Code in the csc.sys driver</description></item><item><title>TfSysMon.sys</title><link>https://www.loldrivers.io/drivers/bd9f084e-b235-4978-bf2a-5f1dc02937df/</link><guid>https://www.loldrivers.io/drivers/bd9f084e-b235-4978-bf2a-5f1dc02937df/</guid><pubDate>Thu, 15 Aug 2024 00:00:00 GMT</pubDate><description></description></item><item><title>Chaos-Rootkit.sys</title><link>https://www.loldrivers.io/drivers/de62baae-872d-4e9a-b6d9-b0ac99854c66/</link><guid>https://www.loldrivers.io/drivers/de62baae-872d-4e9a-b6d9-b0ac99854c66/</guid><pubDate>Thu, 20 Jun 2024 00:00:00 GMT</pubDate><description>Chaos-Rootkit is a x64 ring0 rootkit with process hiding, privilege escalation, and capabilities for protecting and unprotecting processes and ability to restrict access to files except for whitelisted process work seamlessly on the latest Windows versions.</description></item><item><title>fildds.sys</title><link>https://www.loldrivers.io/drivers/af98f6e6-f19e-4705-a7b9-e7ee7377447b/</link><guid>https://www.loldrivers.io/drivers/af98f6e6-f19e-4705-a7b9-e7ee7377447b/</guid><pubDate>Thu, 20 Jun 2024 00:00:00 GMT</pubDate><description>Twister Antivirus, fildds.sys, DoS2
CVE-2023-1444
From IoControlCode 0x8011206B, a normal user can cause DoS due to writing into null address.</description></item><item><title>filnk.sys</title><link>https://www.loldrivers.io/drivers/ba91bce3-2cf9-4c44-bbd8-1170a44d23db/</link><guid>https://www.loldrivers.io/drivers/ba91bce3-2cf9-4c44-bbd8-1170a44d23db/</guid><pubDate>Thu, 20 Jun 2024 00:00:00 GMT</pubDate><description>Twister Antivirus, fildds.sys, DoS2

    CVE-2023-1444

    From IoControlCode 0x8011206B, a normal user can cause DoS due to writing into
    null address.</description></item><item><title>filwfp.sys</title><link>https://www.loldrivers.io/drivers/9d4358c3-5d6e-48a0-971e-e2ad7724c106/</link><guid>https://www.loldrivers.io/drivers/9d4358c3-5d6e-48a0-971e-e2ad7724c106/</guid><pubDate>Thu, 20 Jun 2024 00:00:00 GMT</pubDate><description>Twister Antivirus, fildds.sys, DoS2

    CVE-2023-1444

    From IoControlCode 0x8011206B, a normal user can cause DoS due to writing into
    null address.</description></item><item><title>GPU-Z.sys</title><link>https://www.loldrivers.io/drivers/0d6f1b0f-b94d-4254-b3bb-49de61246260/</link><guid>https://www.loldrivers.io/drivers/0d6f1b0f-b94d-4254-b3bb-49de61246260/</guid><pubDate>Thu, 20 Jun 2024 00:00:00 GMT</pubDate><description>Utilized in RealBlindingEDR.</description></item><item><title>wnbios.sys</title><link>https://www.loldrivers.io/drivers/baa168cd-eba2-42e4-95e9-47cb4b2f9094/</link><guid>https://www.loldrivers.io/drivers/baa168cd-eba2-42e4-95e9-47cb4b2f9094/</guid><pubDate>Thu, 20 Jun 2024 00:00:00 GMT</pubDate><description>Utilized in RealBlindingEDR.</description></item><item><title>ACE-BASE.sys</title><link>https://www.loldrivers.io/drivers/ff77b58d-e143-4f61-92de-c0d9bc0af7d5/</link><guid>https://www.loldrivers.io/drivers/ff77b58d-e143-4f61-92de-c0d9bc0af7d5/</guid><pubDate>Thu, 22 Feb 2024 00:00:00 GMT</pubDate><description>Allows privilege escalation from regular user to System or PPL</description></item><item><title>kavservice.bin</title><link>https://www.loldrivers.io/drivers/77157886-00f9-4f6e-b217-d896813b630f/</link><guid>https://www.loldrivers.io/drivers/77157886-00f9-4f6e-b217-d896813b630f/</guid><pubDate>Wed, 24 Jan 2024 00:00:00 GMT</pubDate><description></description></item><item><title>msr.sys</title><link>https://www.loldrivers.io/drivers/ee6fa2de-d388-416c-862d-24385c152fad/</link><guid>https://www.loldrivers.io/drivers/ee6fa2de-d388-416c-862d-24385c152fad/</guid><pubDate>Sat, 02 Dec 2023 00:00:00 GMT</pubDate><description>Identified on the MSFT Driver Block list, non-admin can write MSR.</description></item><item><title>DcProtect.sys</title><link>https://www.loldrivers.io/drivers/7cee2ce8-7881-4a9a-bb18-61587c95f4a2/</link><guid>https://www.loldrivers.io/drivers/7cee2ce8-7881-4a9a-bb18-61587c95f4a2/</guid><pubDate>Thu, 30 Nov 2023 00:00:00 GMT</pubDate><description>bundled with chinese application &quot;DrvCeo&quot; is a set of rootkits. The malicious functionality. prevents registry value writing where the registry key or value includes &quot;dcprotect&quot; or &quot;drvceo&quot;. Prevents file deletion if pathname contains &quot;driverdownload&quot;, &quot;program files\sysceo&quot;, &quot;program files (x86)\sysceo&quot;</description></item><item><title>truesight.sys</title><link>https://www.loldrivers.io/drivers/e0e93453-1007-4799-ad02-9b461b7e0398/</link><guid>https://www.loldrivers.io/drivers/e0e93453-1007-4799-ad02-9b461b7e0398/</guid><pubDate>Fri, 10 Nov 2023 00:00:00 GMT</pubDate><description>This is a C# AV/EDR Killer using Rogue Anti-Malware Driver 3.3. This driver is not present in the loldrivers or Windows blocklist at the time of this writing. The only reason I&apos;m making this public is because the company has already published a fix in version 3.4, and Microsoft will likely block this driver soon. This driver can be used in Windows 23H2 with HVCI enabled, loldrivers blocklist, or WDAC enabled. HVCI is designed to ensure the integrity of code executed in the kernel, but it cannot protect against all possible vulnerabilities or actions that can be performed through drivers or system interfaces.</description></item><item><title>AODDriver.sys</title><link>https://www.loldrivers.io/drivers/a3c52cbe-90ca-432c-9520-761b60e7d9cb/</link><guid>https://www.loldrivers.io/drivers/a3c52cbe-90ca-432c-9520-761b60e7d9cb/</guid><pubDate>Thu, 02 Nov 2023 00:00:00 GMT</pubDate><description>The Carbon Black Threat Analysis Unit (TAU) discovered 34 unique vulnerable drivers (237 file hashes) accepting firmware access. Six allow kernel memory access. All give full control of the devices to non-admin users. By exploiting the vulnerable drivers, an attacker without the system privilege may erase/alter firmware, and/or elevate privileges. As of the time of writing in October 2023, the filenames of the vulnerable drivers have not been made public until now.</description></item><item><title>atlAccess.sys</title><link>https://www.loldrivers.io/drivers/fb783760-cb3f-4cf4-b4ac-8edb756b9821/</link><guid>https://www.loldrivers.io/drivers/fb783760-cb3f-4cf4-b4ac-8edb756b9821/</guid><pubDate>Thu, 02 Nov 2023 00:00:00 GMT</pubDate><description>The Carbon Black Threat Analysis Unit (TAU) discovered 34 unique vulnerable drivers (237 file hashes) accepting firmware access. Six allow kernel memory access. All give full control of the devices to non-admin users. By exploiting the vulnerable drivers, an attacker without the system privilege may erase/alter firmware, and/or elevate privileges. As of the time of writing in October 2023, the filenames of the vulnerable drivers have not been made public until now.</description></item><item><title>avalueio.sys</title><link>https://www.loldrivers.io/drivers/4f0a65a7-9a01-40cb-8d95-0844515103e6/</link><guid>https://www.loldrivers.io/drivers/4f0a65a7-9a01-40cb-8d95-0844515103e6/</guid><pubDate>Thu, 02 Nov 2023 00:00:00 GMT</pubDate><description>The Carbon Black Threat Analysis Unit (TAU) discovered 34 unique vulnerable drivers (237 file hashes) accepting firmware access. Six allow kernel memory access. All give full control of the devices to non-admin users. By exploiting the vulnerable drivers, an attacker without the system privilege may erase/alter firmware, and/or elevate privileges. As of the time of writing in October 2023, the filenames of the vulnerable drivers have not been made public until now.</description></item><item><title>cg6kwin2k.sys</title><link>https://www.loldrivers.io/drivers/fda3ff67-12dc-488c-a4c2-603f5bf420bd/</link><guid>https://www.loldrivers.io/drivers/fda3ff67-12dc-488c-a4c2-603f5bf420bd/</guid><pubDate>Thu, 02 Nov 2023 00:00:00 GMT</pubDate><description>Sangoma cg6kwin2k versions before 2.1.7.0 expose IOCTLs without sufficient access control. A low-privilege user can perform I/O against arbitrary hardware ports or physical addresses, enabling firmware erasure or modification.</description></item><item><title>ComputerZ.Sys</title><link>https://www.loldrivers.io/drivers/9bf033e4-7295-4b63-8772-638b76851741/</link><guid>https://www.loldrivers.io/drivers/9bf033e4-7295-4b63-8772-638b76851741/</guid><pubDate>Thu, 02 Nov 2023 00:00:00 GMT</pubDate><description>The Carbon Black Threat Analysis Unit (TAU) discovered 34 unique vulnerable drivers (237 file hashes) accepting firmware access. Six allow kernel memory access. All give full control of the devices to non-admin users. By exploiting the vulnerable drivers, an attacker without the system privilege may erase/alter firmware, and/or elevate privileges. As of the time of writing in October 2023, the filenames of the vulnerable drivers have not been made public until now.</description></item><item><title>CP2X72C.SYS</title><link>https://www.loldrivers.io/drivers/a08ee79f-801d-4b98-996f-55f6a72ac5f7/</link><guid>https://www.loldrivers.io/drivers/a08ee79f-801d-4b98-996f-55f6a72ac5f7/</guid><pubDate>Thu, 02 Nov 2023 00:00:00 GMT</pubDate><description>The Carbon Black Threat Analysis Unit (TAU) discovered 34 unique vulnerable drivers (237 file hashes) accepting firmware access. Six allow kernel memory access. All give full control of the devices to non-admin users. By exploiting the vulnerable drivers, an attacker without the system privilege may erase/alter firmware, and/or elevate privileges. As of the time of writing in October 2023, the filenames of the vulnerable drivers have not been made public until now.</description></item><item><title>dellbios.sys</title><link>https://www.loldrivers.io/drivers/fa612342-5ae0-4e69-ad9c-14d574d9fb1e/</link><guid>https://www.loldrivers.io/drivers/fa612342-5ae0-4e69-ad9c-14d574d9fb1e/</guid><pubDate>Thu, 02 Nov 2023 00:00:00 GMT</pubDate><description>The Carbon Black Threat Analysis Unit (TAU) discovered 34 unique vulnerable drivers (237 file hashes) accepting firmware access. Six allow kernel memory access. All give full control of the devices to non-admin users. By exploiting the vulnerable drivers, an attacker without the system privilege may erase/alter firmware, and/or elevate privileges. As of the time of writing in October 2023, the filenames of the vulnerable drivers have not been made public until now.</description></item><item><title>ecsiodriverx64.sys</title><link>https://www.loldrivers.io/drivers/0f749d4e-145e-4b8e-bea6-47003d228043/</link><guid>https://www.loldrivers.io/drivers/0f749d4e-145e-4b8e-bea6-47003d228043/</guid><pubDate>Thu, 02 Nov 2023 00:00:00 GMT</pubDate><description>The Carbon Black Threat Analysis Unit (TAU) discovered 34 unique vulnerable drivers (237 file hashes) accepting firmware access. Six allow kernel memory access. All give full control of the devices to non-admin users. By exploiting the vulnerable drivers, an attacker without the system privilege may erase/alter firmware, and/or elevate privileges. As of the time of writing in October 2023, the filenames of the vulnerable drivers have not been made public until now.</description></item><item><title>FH-EtherCAT_DIO.sys</title><link>https://www.loldrivers.io/drivers/f16f82de-1ad0-47d8-a869-2c10ed25d9f1/</link><guid>https://www.loldrivers.io/drivers/f16f82de-1ad0-47d8-a869-2c10ed25d9f1/</guid><pubDate>Thu, 02 Nov 2023 00:00:00 GMT</pubDate><description>The Carbon Black Threat Analysis Unit (TAU) discovered 34 unique vulnerable drivers (237 file hashes) accepting firmware access. Six allow kernel memory access. All give full control of the devices to non-admin users. By exploiting the vulnerable drivers, an attacker without the system privilege may erase/alter firmware, and/or elevate privileges. As of the time of writing in October 2023, the filenames of the vulnerable drivers have not been made public until now.</description></item><item><title>FPCIE2COM.sys</title><link>https://www.loldrivers.io/drivers/9543c507-9b10-4de8-89b9-42a4f24c99ec/</link><guid>https://www.loldrivers.io/drivers/9543c507-9b10-4de8-89b9-42a4f24c99ec/</guid><pubDate>Thu, 02 Nov 2023 00:00:00 GMT</pubDate><description>FINTEK FPCIE2COM exposes FILE_ANY_ACCESS IOCTLs through \DosDevices\FPCIE2COM that map caller-selected physical addresses for byte reads and writes. It also permits raw PCI configuration access through I/O ports 0xCF8 and 0xCFC, creating privileged hardware-control primitives suitable for kernel or firmware tampering.</description></item><item><title>GEDevDrv.SYS</title><link>https://www.loldrivers.io/drivers/e769d1f6-8a38-426f-b5e7-447241204ee1/</link><guid>https://www.loldrivers.io/drivers/e769d1f6-8a38-426f-b5e7-447241204ee1/</guid><pubDate>Thu, 02 Nov 2023 00:00:00 GMT</pubDate><description>The Carbon Black Threat Analysis Unit (TAU) discovered 34 unique vulnerable drivers (237 file hashes) accepting firmware access. Six allow kernel memory access. All give full control of the devices to non-admin users. By exploiting the vulnerable drivers, an attacker without the system privilege may erase/alter firmware, and/or elevate privileges. As of the time of writing in October 2023, the filenames of the vulnerable drivers have not been made public until now.</description></item><item><title>GtcKmdfBs.sys</title><link>https://www.loldrivers.io/drivers/b0dedc3f-6e4b-497a-aade-390cbf4beebb/</link><guid>https://www.loldrivers.io/drivers/b0dedc3f-6e4b-497a-aade-390cbf4beebb/</guid><pubDate>Thu, 02 Nov 2023 00:00:00 GMT</pubDate><description>The Carbon Black Threat Analysis Unit (TAU) discovered 34 unique vulnerable drivers (237 file hashes) accepting firmware access. Six allow kernel memory access. All give full control of the devices to non-admin users. By exploiting the vulnerable drivers, an attacker without the system privilege may erase/alter firmware, and/or elevate privileges. As of the time of writing in October 2023, the filenames of the vulnerable drivers have not been made public until now.</description></item><item><title>hwdetectng.sys</title><link>https://www.loldrivers.io/drivers/f92f4c60-b39c-4726-ba74-dcab7f653ae2/</link><guid>https://www.loldrivers.io/drivers/f92f4c60-b39c-4726-ba74-dcab7f653ae2/</guid><pubDate>Thu, 02 Nov 2023 00:00:00 GMT</pubDate><description>The Carbon Black Threat Analysis Unit (TAU) discovered 34 unique vulnerable drivers (237 file hashes) accepting firmware access. Six allow kernel memory access. All give full control of the devices to non-admin users. By exploiting the vulnerable drivers, an attacker without the system privilege may erase/alter firmware, and/or elevate privileges. As of the time of writing in October 2023, the filenames of the vulnerable drivers have not been made public until now.</description></item><item><title>IoAccess.sys</title><link>https://www.loldrivers.io/drivers/c08c03ff-a7b7-4282-a9fc-265ae88dc244/</link><guid>https://www.loldrivers.io/drivers/c08c03ff-a7b7-4282-a9fc-265ae88dc244/</guid><pubDate>Thu, 02 Nov 2023 00:00:00 GMT</pubDate><description>The Carbon Black Threat Analysis Unit (TAU) discovered 34 unique vulnerable drivers (237 file hashes) accepting firmware access. Six allow kernel memory access. All give full control of the devices to non-admin users. By exploiting the vulnerable drivers, an attacker without the system privilege may erase/alter firmware, and/or elevate privileges. As of the time of writing in October 2023, the filenames of the vulnerable drivers have not been made public until now.</description></item><item><title>kerneld.amd64</title><link>https://www.loldrivers.io/drivers/3aa6e630-59be-4a15-a30c-aaed4c1edaf0/</link><guid>https://www.loldrivers.io/drivers/3aa6e630-59be-4a15-a30c-aaed4c1edaf0/</guid><pubDate>Thu, 02 Nov 2023 00:00:00 GMT</pubDate><description>The Carbon Black Threat Analysis Unit (TAU) discovered 34 unique vulnerable drivers (237 file hashes) accepting firmware access. Six allow kernel memory access. All give full control of the devices to non-admin users. By exploiting the vulnerable drivers, an attacker without the system privilege may erase/alter firmware, and/or elevate privileges. As of the time of writing in October 2023, the filenames of the vulnerable drivers have not been made public until now.</description></item><item><title>ngiodriver.sys</title><link>https://www.loldrivers.io/drivers/b8339454-0e84-4a5b-92d0-6a626ced6677/</link><guid>https://www.loldrivers.io/drivers/b8339454-0e84-4a5b-92d0-6a626ced6677/</guid><pubDate>Thu, 02 Nov 2023 00:00:00 GMT</pubDate><description>The Carbon Black Threat Analysis Unit (TAU) discovered 34 unique vulnerable drivers (237 file hashes) accepting firmware access. Six allow kernel memory access. All give full control of the devices to non-admin users. By exploiting the vulnerable drivers, an attacker without the system privilege may erase/alter firmware, and/or elevate privileges. As of the time of writing in October 2023, the filenames of the vulnerable drivers have not been made public until now.</description></item><item><title>nvaudio.sys</title><link>https://www.loldrivers.io/drivers/837ad058-65f4-4b75-8f21-b842e48db8a5/</link><guid>https://www.loldrivers.io/drivers/837ad058-65f4-4b75-8f21-b842e48db8a5/</guid><pubDate>Thu, 02 Nov 2023 00:00:00 GMT</pubDate><description>The Carbon Black Threat Analysis Unit (TAU) discovered 34 unique vulnerable drivers (237 file hashes) accepting firmware access. Six allow kernel memory access. All give full control of the devices to non-admin users. By exploiting the vulnerable drivers, an attacker without the system privilege may erase/alter firmware, and/or elevate privileges. As of the time of writing in October 2023, the filenames of the vulnerable drivers have not been made public until now.</description></item><item><title>nvoclock.sys</title><link>https://www.loldrivers.io/drivers/3d7da79b-fe34-45cd-a0c9-d4432d40611c/</link><guid>https://www.loldrivers.io/drivers/3d7da79b-fe34-45cd-a0c9-d4432d40611c/</guid><pubDate>Thu, 02 Nov 2023 00:00:00 GMT</pubDate><description>The Carbon Black Threat Analysis Unit (TAU) discovered 34 unique vulnerable drivers (237 file hashes) accepting firmware access. Six allow kernel memory access. All give full control of the devices to non-admin users. By exploiting the vulnerable drivers, an attacker without the system privilege may erase/alter firmware, and/or elevate privileges. As of the time of writing in October 2023, the filenames of the vulnerable drivers have not been made public until now.</description></item><item><title>PDFWKRNL.sys</title><link>https://www.loldrivers.io/drivers/fded7e63-0470-40fe-97ed-aa83fd027bad/</link><guid>https://www.loldrivers.io/drivers/fded7e63-0470-40fe-97ed-aa83fd027bad/</guid><pubDate>Thu, 02 Nov 2023 00:00:00 GMT</pubDate><description>The Carbon Black Threat Analysis Unit (TAU) discovered 34 unique vulnerable drivers (237 file hashes) accepting firmware access. Six allow kernel memory access. All give full control of the devices to non-admin users. By exploiting the vulnerable drivers, an attacker without the system privilege may erase/alter firmware, and/or elevate privileges. As of the time of writing in October 2023, the filenames of the vulnerable drivers have not been made public until now.</description></item><item><title>phymem_ext64.sys</title><link>https://www.loldrivers.io/drivers/2b918b1a-badb-4a85-9214-961607b21219/</link><guid>https://www.loldrivers.io/drivers/2b918b1a-badb-4a85-9214-961607b21219/</guid><pubDate>Thu, 02 Nov 2023 00:00:00 GMT</pubDate><description>The Carbon Black Threat Analysis Unit (TAU) discovered 34 unique vulnerable drivers (237 file hashes) accepting firmware access. Six allow kernel memory access. All give full control of the devices to non-admin users. By exploiting the vulnerable drivers, an attacker without the system privilege may erase/alter firmware, and/or elevate privileges. As of the time of writing in October 2023, the filenames of the vulnerable drivers have not been made public until now.</description></item><item><title>RadHwMgr.sys</title><link>https://www.loldrivers.io/drivers/7bb4d807-9a66-48ff-9fb7-82780f3b015e/</link><guid>https://www.loldrivers.io/drivers/7bb4d807-9a66-48ff-9fb7-82780f3b015e/</guid><pubDate>Thu, 02 Nov 2023 00:00:00 GMT</pubDate><description>The Carbon Black Threat Analysis Unit (TAU) discovered 34 unique vulnerable drivers (237 file hashes) accepting firmware access. Six allow kernel memory access. All give full control of the devices to non-admin users. By exploiting the vulnerable drivers, an attacker without the system privilege may erase/alter firmware, and/or elevate privileges. As of the time of writing in October 2023, the filenames of the vulnerable drivers have not been made public until now.</description></item><item><title>rtif.sys</title><link>https://www.loldrivers.io/drivers/36227ce7-2bf6-4963-bfae-c399000a1079/</link><guid>https://www.loldrivers.io/drivers/36227ce7-2bf6-4963-bfae-c399000a1079/</guid><pubDate>Thu, 02 Nov 2023 00:00:00 GMT</pubDate><description>The Carbon Black Threat Analysis Unit (TAU) discovered 34 unique vulnerable drivers (237 file hashes) accepting firmware access. Six allow kernel memory access. All give full control of the devices to non-admin users. By exploiting the vulnerable drivers, an attacker without the system privilege may erase/alter firmware, and/or elevate privileges. As of the time of writing in October 2023, the filenames of the vulnerable drivers have not been made public until now.</description></item><item><title>rtport.sys</title><link>https://www.loldrivers.io/drivers/8ecc8439-0554-40d0-9130-c02941deadbe/</link><guid>https://www.loldrivers.io/drivers/8ecc8439-0554-40d0-9130-c02941deadbe/</guid><pubDate>Thu, 02 Nov 2023 00:00:00 GMT</pubDate><description>The Carbon Black Threat Analysis Unit (TAU) discovered 34 unique vulnerable drivers (237 file hashes) accepting firmware access. Six allow kernel memory access. All give full control of the devices to non-admin users. By exploiting the vulnerable drivers, an attacker without the system privilege may erase/alter firmware, and/or elevate privileges. As of the time of writing in October 2023, the filenames of the vulnerable drivers have not been made public until now.</description></item><item><title>SBIOSIO64.sys</title><link>https://www.loldrivers.io/drivers/cf805b21-4611-4983-a8b6-271373a45057/</link><guid>https://www.loldrivers.io/drivers/cf805b21-4611-4983-a8b6-271373a45057/</guid><pubDate>Thu, 02 Nov 2023 00:00:00 GMT</pubDate><description>The Carbon Black Threat Analysis Unit (TAU) discovered 34 unique vulnerable drivers (237 file hashes) accepting firmware access. Six allow kernel memory access. All give full control of the devices to non-admin users. By exploiting the vulnerable drivers, an attacker without the system privilege may erase/alter firmware, and/or elevate privileges. As of the time of writing in October 2023, the filenames of the vulnerable drivers have not been made public until now.</description></item><item><title>sepdrv3_1.sys</title><link>https://www.loldrivers.io/drivers/942f58d2-1300-4957-98a0-5f8d601bf55b/</link><guid>https://www.loldrivers.io/drivers/942f58d2-1300-4957-98a0-5f8d601bf55b/</guid><pubDate>Thu, 02 Nov 2023 00:00:00 GMT</pubDate><description>The Carbon Black Threat Analysis Unit (TAU) discovered 34 unique vulnerable drivers (237 file hashes) accepting firmware access. Six allow kernel memory access. All give full control of the devices to non-admin users. By exploiting the vulnerable drivers, an attacker without the system privilege may erase/alter firmware, and/or elevate privileges. As of the time of writing in October 2023, the filenames of the vulnerable drivers have not been made public until now.</description></item><item><title>SMARTEIO64.SYS</title><link>https://www.loldrivers.io/drivers/2a7a59c1-35b8-42b6-a560-2fbf4247a584/</link><guid>https://www.loldrivers.io/drivers/2a7a59c1-35b8-42b6-a560-2fbf4247a584/</guid><pubDate>Thu, 02 Nov 2023 00:00:00 GMT</pubDate><description>The Carbon Black Threat Analysis Unit (TAU) discovered 34 unique vulnerable drivers (237 file hashes) accepting firmware access. Six allow kernel memory access. All give full control of the devices to non-admin users. By exploiting the vulnerable drivers, an attacker without the system privilege may erase/alter firmware, and/or elevate privileges. As of the time of writing in October 2023, the filenames of the vulnerable drivers have not been made public until now.</description></item><item><title>stdcdrv64.sys</title><link>https://www.loldrivers.io/drivers/f33c2e80-7b01-416b-821a-ed06db4b6511/</link><guid>https://www.loldrivers.io/drivers/f33c2e80-7b01-416b-821a-ed06db4b6511/</guid><pubDate>Thu, 02 Nov 2023 00:00:00 GMT</pubDate><description>The Carbon Black Threat Analysis Unit (TAU) discovered 34 unique vulnerable drivers (237 file hashes) accepting firmware access. Six allow kernel memory access. All give full control of the devices to non-admin users. By exploiting the vulnerable drivers, an attacker without the system privilege may erase/alter firmware, and/or elevate privileges. As of the time of writing in October 2023, the filenames of the vulnerable drivers have not been made public until now.</description></item><item><title>stdcdrvws64.sys</title><link>https://www.loldrivers.io/drivers/dc3fdbd3-601a-4d2a-bf34-d2e84c6ff1d3/</link><guid>https://www.loldrivers.io/drivers/dc3fdbd3-601a-4d2a-bf34-d2e84c6ff1d3/</guid><pubDate>Thu, 02 Nov 2023 00:00:00 GMT</pubDate><description>The Carbon Black Threat Analysis Unit (TAU) discovered 34 unique vulnerable drivers (237 file hashes) accepting firmware access. Six allow kernel memory access. All give full control of the devices to non-admin users. By exploiting the vulnerable drivers, an attacker without the system privilege may erase/alter firmware, and/or elevate privileges. As of the time of writing in October 2023, the filenames of the vulnerable drivers have not been made public until now.</description></item><item><title>sysconp.sys</title><link>https://www.loldrivers.io/drivers/62f76f62-ef82-49ea-a26f-36e5727e8d83/</link><guid>https://www.loldrivers.io/drivers/62f76f62-ef82-49ea-a26f-36e5727e8d83/</guid><pubDate>Thu, 02 Nov 2023 00:00:00 GMT</pubDate><description>The Carbon Black Threat Analysis Unit (TAU) discovered 34 unique vulnerable drivers (237 file hashes) accepting firmware access. Six allow kernel memory access. All give full control of the devices to non-admin users. By exploiting the vulnerable drivers, an attacker without the system privilege may erase/alter firmware, and/or elevate privileges. As of the time of writing in October 2023, the filenames of the vulnerable drivers have not been made public until now.</description></item><item><title>SysInfoDetectorX64.sys</title><link>https://www.loldrivers.io/drivers/c4eab0c0-caf2-42b9-84f1-b4690d3db0d4/</link><guid>https://www.loldrivers.io/drivers/c4eab0c0-caf2-42b9-84f1-b4690d3db0d4/</guid><pubDate>Thu, 02 Nov 2023 00:00:00 GMT</pubDate><description>The Carbon Black Threat Analysis Unit (TAU) discovered 34 unique vulnerable drivers (237 file hashes) accepting firmware access. Six allow kernel memory access. All give full control of the devices to non-admin users. By exploiting the vulnerable drivers, an attacker without the system privilege may erase/alter firmware, and/or elevate privileges. As of the time of writing in October 2023, the filenames of the vulnerable drivers have not been made public until now.</description></item><item><title>tdeio64.sys</title><link>https://www.loldrivers.io/drivers/4f47c65e-2e73-4855-813a-5a823ae845a8/</link><guid>https://www.loldrivers.io/drivers/4f47c65e-2e73-4855-813a-5a823ae845a8/</guid><pubDate>Thu, 02 Nov 2023 00:00:00 GMT</pubDate><description>The Carbon Black Threat Analysis Unit (TAU) discovered 34 unique vulnerable drivers (237 file hashes) accepting firmware access. Six allow kernel memory access. All give full control of the devices to non-admin users. By exploiting the vulnerable drivers, an attacker without the system privilege may erase/alter firmware, and/or elevate privileges. As of the time of writing in October 2023, the filenames of the vulnerable drivers have not been made public until now.</description></item><item><title>TdkLib64.sys</title><link>https://www.loldrivers.io/drivers/933f5671-e995-4976-8392-52d34dcd4e05/</link><guid>https://www.loldrivers.io/drivers/933f5671-e995-4976-8392-52d34dcd4e05/</guid><pubDate>Thu, 02 Nov 2023 00:00:00 GMT</pubDate><description>The Carbon Black Threat Analysis Unit (TAU) discovered 34 unique vulnerable drivers (237 file hashes) accepting firmware access. Six allow kernel memory access. All give full control of the devices to non-admin users. By exploiting the vulnerable drivers, an attacker without the system privilege may erase/alter firmware, and/or elevate privileges. As of the time of writing in October 2023, the filenames of the vulnerable drivers have not been made public until now.</description></item><item><title>VdBSv64.sys</title><link>https://www.loldrivers.io/drivers/5901421f-7929-487d-87bd-632f29290352/</link><guid>https://www.loldrivers.io/drivers/5901421f-7929-487d-87bd-632f29290352/</guid><pubDate>Thu, 02 Nov 2023 00:00:00 GMT</pubDate><description>The Carbon Black Threat Analysis Unit (TAU) discovered 34 unique vulnerable drivers (237 file hashes) accepting firmware access. Six allow kernel memory access. All give full control of the devices to non-admin users. By exploiting the vulnerable drivers, an attacker without the system privilege may erase/alter firmware, and/or elevate privileges. As of the time of writing in October 2023, the filenames of the vulnerable drivers have not been made public until now.</description></item><item><title>WiRwaDrv.sys</title><link>https://www.loldrivers.io/drivers/a4795ab6-d908-44cf-9ebf-a47db367d385/</link><guid>https://www.loldrivers.io/drivers/a4795ab6-d908-44cf-9ebf-a47db367d385/</guid><pubDate>Thu, 02 Nov 2023 00:00:00 GMT</pubDate><description>The Carbon Black Threat Analysis Unit (TAU) discovered 34 unique vulnerable drivers (237 file hashes) accepting firmware access. Six allow kernel memory access. All give full control of the devices to non-admin users. By exploiting the vulnerable drivers, an attacker without the system privilege may erase/alter firmware, and/or elevate privileges. As of the time of writing in October 2023, the filenames of the vulnerable drivers have not been made public until now.</description></item><item><title>AsmIo64.sys</title><link>https://www.loldrivers.io/drivers/257d425f-f660-466c-8bee-c24cccf06daa/</link><guid>https://www.loldrivers.io/drivers/257d425f-f660-466c-8bee-c24cccf06daa/</guid><pubDate>Thu, 12 Oct 2023 00:00:00 GMT</pubDate><description></description></item><item><title>gpcidrv64.sys</title><link>https://www.loldrivers.io/drivers/6736cbe7-33ea-4488-b464-231c0b8d1049/</link><guid>https://www.loldrivers.io/drivers/6736cbe7-33ea-4488-b464-231c0b8d1049/</guid><pubDate>Thu, 12 Oct 2023 00:00:00 GMT</pubDate><description></description></item><item><title>iscflashx64.sys</title><link>https://www.loldrivers.io/drivers/97ed6c7b-be4c-4f60-9157-c788a555ca9f/</link><guid>https://www.loldrivers.io/drivers/97ed6c7b-be4c-4f60-9157-c788a555ca9f/</guid><pubDate>Thu, 12 Oct 2023 00:00:00 GMT</pubDate><description>CVE-2021-33834</description></item><item><title>wsdkd.sys</title><link>https://www.loldrivers.io/drivers/a8f2da2a-369c-4b4d-9a00-d7a892b9f7c3/</link><guid>https://www.loldrivers.io/drivers/a8f2da2a-369c-4b4d-9a00-d7a892b9f7c3/</guid><pubDate>Tue, 12 Sep 2023 00:00:00 GMT</pubDate><description>A vulnerability was found in Watchdog Anti-Virus 1.4.214.0. It has been rated as critical. Affected by this issue is the function 0x80002008 in the library wsdk-driver.sys of the component IoControlCode Handler. The manipulation leads to improper access controls. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. VDB-223298 is the identifier assigned to this vulnerability.</description></item><item><title>1fc7aeeff3ab19004d2e53eae8160ab1.sys</title><link>https://www.loldrivers.io/drivers/aaf8ce1a-e11b-4929-96e0-5ec0666cef2c/</link><guid>https://www.loldrivers.io/drivers/aaf8ce1a-e11b-4929-96e0-5ec0666cef2c/</guid><pubDate>Mon, 31 Jul 2023 00:00:00 GMT</pubDate><description>Cisco Talos has identified multiple versions of an undocumented malicious driver named “RedDriver,” a driver-based browser hijacker that uses the Windows Filtering Platform (WFP) to intercept browser traffic. RedDriver has been active since at least 2021. RedDriver utilizes HookSignTool to forge its signature timestamp to bypass Windows driver-signing policies. Code from multiple open-source tools has been used in the development of RedDriver&apos;s infection chain, including HP-Socket and a custom implementation of ReflectiveLoader. The authors of RedDriver appear to be skilled in driver development and have deep knowledge of the Windows operating system. This threat appears to target native Chinese speakers, as it searches for Chinese language browsers to hijack. Additionally, the authors are likely Chinese speakers themselves.</description></item><item><title>4118b86e490aed091b1a219dba45f332.sys</title><link>https://www.loldrivers.io/drivers/b32d8d7d-0dc2-4d09-a306-8efc4caf1839/</link><guid>https://www.loldrivers.io/drivers/b32d8d7d-0dc2-4d09-a306-8efc4caf1839/</guid><pubDate>Mon, 31 Jul 2023 00:00:00 GMT</pubDate><description>Cisco Talos has identified multiple versions of an undocumented malicious driver named “RedDriver,” a driver-based browser hijacker that uses the Windows Filtering Platform (WFP) to intercept browser traffic. RedDriver has been active since at least 2021. RedDriver utilizes HookSignTool to forge its signature timestamp to bypass Windows driver-signing policies. Code from multiple open-source tools has been used in the development of RedDriver&apos;s infection chain, including HP-Socket and a custom implementation of ReflectiveLoader. The authors of RedDriver appear to be skilled in driver development and have deep knowledge of the Windows operating system. This threat appears to target native Chinese speakers, as it searches for Chinese language browsers to hijack. Additionally, the authors are likely Chinese speakers themselves.</description></item><item><title>4748696211bd56c2d93c21cab91e82a5.sys</title><link>https://www.loldrivers.io/drivers/2d6c1da6-17e2-4385-ad93-1430f83bde83/</link><guid>https://www.loldrivers.io/drivers/2d6c1da6-17e2-4385-ad93-1430f83bde83/</guid><pubDate>Mon, 31 Jul 2023 00:00:00 GMT</pubDate><description>Cisco Talos has identified multiple versions of an undocumented malicious driver named “RedDriver,” a driver-based browser hijacker that uses the Windows Filtering Platform (WFP) to intercept browser traffic. RedDriver has been active since at least 2021. RedDriver utilizes HookSignTool to forge its signature timestamp to bypass Windows driver-signing policies. Code from multiple open-source tools has been used in the development of RedDriver&apos;s infection chain, including HP-Socket and a custom implementation of ReflectiveLoader. The authors of RedDriver appear to be skilled in driver development and have deep knowledge of the Windows operating system. This threat appears to target native Chinese speakers, as it searches for Chinese language browsers to hijack. Additionally, the authors are likely Chinese speakers themselves.</description></item><item><title>5a4fe297c7d42539303137b6d75b150d.sys</title><link>https://www.loldrivers.io/drivers/75b9b0c5-dd3e-4cf3-a693-c80f2feabb6a/</link><guid>https://www.loldrivers.io/drivers/75b9b0c5-dd3e-4cf3-a693-c80f2feabb6a/</guid><pubDate>Mon, 31 Jul 2023 00:00:00 GMT</pubDate><description>Cisco Talos has identified multiple versions of an undocumented malicious driver named “RedDriver,” a driver-based browser hijacker that uses the Windows Filtering Platform (WFP) to intercept browser traffic. RedDriver has been active since at least 2021. RedDriver utilizes HookSignTool to forge its signature timestamp to bypass Windows driver-signing policies. Code from multiple open-source tools has been used in the development of RedDriver&apos;s infection chain, including HP-Socket and a custom implementation of ReflectiveLoader. The authors of RedDriver appear to be skilled in driver development and have deep knowledge of the Windows operating system. This threat appears to target native Chinese speakers, as it searches for Chinese language browsers to hijack. Additionally, the authors are likely Chinese speakers themselves.</description></item><item><title>6771b13a53b9c7449d4891e427735ea2.sys</title><link>https://www.loldrivers.io/drivers/ddca6daf-4932-4e82-ad3c-d92d47632ea4/</link><guid>https://www.loldrivers.io/drivers/ddca6daf-4932-4e82-ad3c-d92d47632ea4/</guid><pubDate>Mon, 31 Jul 2023 00:00:00 GMT</pubDate><description>Cisco Talos has identified multiple versions of an undocumented malicious driver named “RedDriver,” a driver-based browser hijacker that uses the Windows Filtering Platform (WFP) to intercept browser traffic. RedDriver has been active since at least 2021. RedDriver utilizes HookSignTool to forge its signature timestamp to bypass Windows driver-signing policies. Code from multiple open-source tools has been used in the development of RedDriver&apos;s infection chain, including HP-Socket and a custom implementation of ReflectiveLoader. The authors of RedDriver appear to be skilled in driver development and have deep knowledge of the Windows operating system. This threat appears to target native Chinese speakers, as it searches for Chinese language browsers to hijack. Additionally, the authors are likely Chinese speakers themselves.</description></item><item><title>a236e7d654cd932b7d11cb604629a2d0.sys</title><link>https://www.loldrivers.io/drivers/2866bd72-a4b1-4764-a838-9ed0790c2631/</link><guid>https://www.loldrivers.io/drivers/2866bd72-a4b1-4764-a838-9ed0790c2631/</guid><pubDate>Mon, 31 Jul 2023 00:00:00 GMT</pubDate><description>Cisco Talos has identified multiple versions of an undocumented malicious driver named “RedDriver,” a driver-based browser hijacker that uses the Windows Filtering Platform (WFP) to intercept browser traffic. RedDriver has been active since at least 2021. RedDriver utilizes HookSignTool to forge its signature timestamp to bypass Windows driver-signing policies. Code from multiple open-source tools has been used in the development of RedDriver&apos;s infection chain, including HP-Socket and a custom implementation of ReflectiveLoader. The authors of RedDriver appear to be skilled in driver development and have deep knowledge of the Windows operating system. This threat appears to target native Chinese speakers, as it searches for Chinese language browsers to hijack. Additionally, the authors are likely Chinese speakers themselves.</description></item><item><title>a26363e7b02b13f2b8d697abb90cd5c3.sys</title><link>https://www.loldrivers.io/drivers/ef6b5fe8-6c4b-4b32-8adc-c1d8a83e8558/</link><guid>https://www.loldrivers.io/drivers/ef6b5fe8-6c4b-4b32-8adc-c1d8a83e8558/</guid><pubDate>Mon, 31 Jul 2023 00:00:00 GMT</pubDate><description>Cisco Talos has identified multiple versions of an undocumented malicious driver named “RedDriver,” a driver-based browser hijacker that uses the Windows Filtering Platform (WFP) to intercept browser traffic. RedDriver has been active since at least 2021. RedDriver utilizes HookSignTool to forge its signature timestamp to bypass Windows driver-signing policies. Code from multiple open-source tools has been used in the development of RedDriver&apos;s infection chain, including HP-Socket and a custom implementation of ReflectiveLoader. The authors of RedDriver appear to be skilled in driver development and have deep knowledge of the Windows operating system. This threat appears to target native Chinese speakers, as it searches for Chinese language browsers to hijack. Additionally, the authors are likely Chinese speakers themselves.</description></item><item><title>a9df5964635ef8bd567ae487c3d214c4.sys</title><link>https://www.loldrivers.io/drivers/ac62e709-4aa5-41f4-87b1-b811283d70d1/</link><guid>https://www.loldrivers.io/drivers/ac62e709-4aa5-41f4-87b1-b811283d70d1/</guid><pubDate>Mon, 31 Jul 2023 00:00:00 GMT</pubDate><description>Cisco Talos has identified multiple versions of an undocumented malicious driver named “RedDriver,” a driver-based browser hijacker that uses the Windows Filtering Platform (WFP) to intercept browser traffic. RedDriver has been active since at least 2021. RedDriver utilizes HookSignTool to forge its signature timestamp to bypass Windows driver-signing policies. Code from multiple open-source tools has been used in the development of RedDriver&apos;s infection chain, including HP-Socket and a custom implementation of ReflectiveLoader. The authors of RedDriver appear to be skilled in driver development and have deep knowledge of the Windows operating system. This threat appears to target native Chinese speakers, as it searches for Chinese language browsers to hijack. Additionally, the authors are likely Chinese speakers themselves.</description></item><item><title>be6318413160e589080df02bb3ca6e6a.sys</title><link>https://www.loldrivers.io/drivers/a9ab4412-d484-459b-be97-5975f5ab8094/</link><guid>https://www.loldrivers.io/drivers/a9ab4412-d484-459b-be97-5975f5ab8094/</guid><pubDate>Mon, 31 Jul 2023 00:00:00 GMT</pubDate><description>Cisco Talos has identified multiple versions of an undocumented malicious driver named “RedDriver,” a driver-based browser hijacker that uses the Windows Filtering Platform (WFP) to intercept browser traffic. RedDriver has been active since at least 2021. RedDriver utilizes HookSignTool to forge its signature timestamp to bypass Windows driver-signing policies. Code from multiple open-source tools has been used in the development of RedDriver&apos;s infection chain, including HP-Socket and a custom implementation of ReflectiveLoader. The authors of RedDriver appear to be skilled in driver development and have deep knowledge of the Windows operating system. This threat appears to target native Chinese speakers, as it searches for Chinese language browsers to hijack. Additionally, the authors are likely Chinese speakers themselves.</description></item><item><title>c94f405c5929cfcccc8ad00b42c95083.sys</title><link>https://www.loldrivers.io/drivers/ddefecdd-9410-46d9-8957-e23aac1aba0c/</link><guid>https://www.loldrivers.io/drivers/ddefecdd-9410-46d9-8957-e23aac1aba0c/</guid><pubDate>Mon, 31 Jul 2023 00:00:00 GMT</pubDate><description>Cisco Talos has identified multiple versions of an undocumented malicious driver named “RedDriver,” a driver-based browser hijacker that uses the Windows Filtering Platform (WFP) to intercept browser traffic. RedDriver has been active since at least 2021. RedDriver utilizes HookSignTool to forge its signature timestamp to bypass Windows driver-signing policies. Code from multiple open-source tools has been used in the development of RedDriver&apos;s infection chain, including HP-Socket and a custom implementation of ReflectiveLoader. The authors of RedDriver appear to be skilled in driver development and have deep knowledge of the Windows operating system. This threat appears to target native Chinese speakers, as it searches for Chinese language browsers to hijack. Additionally, the authors are likely Chinese speakers themselves.</description></item><item><title>e29f6311ae87542b3d693c1f38e4e3ad.sys</title><link>https://www.loldrivers.io/drivers/c00f818c-1c90-4b47-bc29-fb949f6efb65/</link><guid>https://www.loldrivers.io/drivers/c00f818c-1c90-4b47-bc29-fb949f6efb65/</guid><pubDate>Mon, 31 Jul 2023 00:00:00 GMT</pubDate><description>Cisco Talos has identified multiple versions of an undocumented malicious driver named “RedDriver,” a driver-based browser hijacker that uses the Windows Filtering Platform (WFP) to intercept browser traffic. RedDriver has been active since at least 2021. RedDriver utilizes HookSignTool to forge its signature timestamp to bypass Windows driver-signing policies. Code from multiple open-source tools has been used in the development of RedDriver&apos;s infection chain, including HP-Socket and a custom implementation of ReflectiveLoader. The authors of RedDriver appear to be skilled in driver development and have deep knowledge of the Windows operating system. This threat appears to target native Chinese speakers, as it searches for Chinese language browsers to hijack. Additionally, the authors are likely Chinese speakers themselves.</description></item><item><title>e939448b28a4edc81f1f974cebf6e7d2.sys</title><link>https://www.loldrivers.io/drivers/4f2edf45-b135-404f-bedc-9583f0bae574/</link><guid>https://www.loldrivers.io/drivers/4f2edf45-b135-404f-bedc-9583f0bae574/</guid><pubDate>Mon, 31 Jul 2023 00:00:00 GMT</pubDate><description>Cisco Talos has identified multiple versions of an undocumented malicious driver named “RedDriver,” a driver-based browser hijacker that uses the Windows Filtering Platform (WFP) to intercept browser traffic. RedDriver has been active since at least 2021. RedDriver utilizes HookSignTool to forge its signature timestamp to bypass Windows driver-signing policies. Code from multiple open-source tools has been used in the development of RedDriver&apos;s infection chain, including HP-Socket and a custom implementation of ReflectiveLoader. The authors of RedDriver appear to be skilled in driver development and have deep knowledge of the Windows operating system. This threat appears to target native Chinese speakers, as it searches for Chinese language browsers to hijack. Additionally, the authors are likely Chinese speakers themselves.</description></item><item><title>ef0e1725aaf0c6c972593f860531a2ea.sys</title><link>https://www.loldrivers.io/drivers/8c2df58f-1e02-4911-ad40-3fa4ed1f4333/</link><guid>https://www.loldrivers.io/drivers/8c2df58f-1e02-4911-ad40-3fa4ed1f4333/</guid><pubDate>Mon, 31 Jul 2023 00:00:00 GMT</pubDate><description>Cisco Talos has identified multiple versions of an undocumented malicious driver named “RedDriver,” a driver-based browser hijacker that uses the Windows Filtering Platform (WFP) to intercept browser traffic. RedDriver has been active since at least 2021. RedDriver utilizes HookSignTool to forge its signature timestamp to bypass Windows driver-signing policies. Code from multiple open-source tools has been used in the development of RedDriver&apos;s infection chain, including HP-Socket and a custom implementation of ReflectiveLoader. The authors of RedDriver appear to be skilled in driver development and have deep knowledge of the Windows operating system. This threat appears to target native Chinese speakers, as it searches for Chinese language browsers to hijack. Additionally, the authors are likely Chinese speakers themselves.</description></item><item><title>fd3b7234419fafc9bdd533f48896ed73_b816c5cd.sys</title><link>https://www.loldrivers.io/drivers/c7f76931-e24c-4d94-9e1f-5a083da581b4/</link><guid>https://www.loldrivers.io/drivers/c7f76931-e24c-4d94-9e1f-5a083da581b4/</guid><pubDate>Tue, 25 Jul 2023 00:00:00 GMT</pubDate><description>The criminals signed their AV-killer malware, closely related to one known as BURNTCIGAR, with a legitimate WHCP certificate</description></item><item><title>asas.sys</title><link>https://www.loldrivers.io/drivers/dbb58de1-a1e5-4c7f-8fe0-4033502b1c63/</link><guid>https://www.loldrivers.io/drivers/dbb58de1-a1e5-4c7f-8fe0-4033502b1c63/</guid><pubDate>Sat, 22 Jul 2023 00:00:00 GMT</pubDate><description>Confirmed vulnerable driver from Microsoft Block List</description></item><item><title>AsrAutoChkUpdDrv_1_0_32.sys</title><link>https://www.loldrivers.io/drivers/02e4a30f-8aa8-4ff0-8e02-1bff1d0f088f/</link><guid>https://www.loldrivers.io/drivers/02e4a30f-8aa8-4ff0-8e02-1bff1d0f088f/</guid><pubDate>Sat, 22 Jul 2023 00:00:00 GMT</pubDate><description>Confirmed vulnerable driver from Microsoft Block List</description></item><item><title>AsrDrv.sys</title><link>https://www.loldrivers.io/drivers/213676bb-ffb9-4d0d-a442-8cefee63acc1/</link><guid>https://www.loldrivers.io/drivers/213676bb-ffb9-4d0d-a442-8cefee63acc1/</guid><pubDate>Sat, 22 Jul 2023 00:00:00 GMT</pubDate><description>Confirmed vulnerable driver from Microsoft Block List</description></item><item><title>atomicredteamcapcom.sys</title><link>https://www.loldrivers.io/drivers/a02e1801-f6fb-41c3-a782-05fdbed44a3c/</link><guid>https://www.loldrivers.io/drivers/a02e1801-f6fb-41c3-a782-05fdbed44a3c/</guid><pubDate>Sat, 22 Jul 2023 00:00:00 GMT</pubDate><description>Confirmed vulnerable driver from Microsoft Block List</description></item><item><title>Blackbone.sys</title><link>https://www.loldrivers.io/drivers/b9b835bd-b720-424b-9160-2442bc4d6e58/</link><guid>https://www.loldrivers.io/drivers/b9b835bd-b720-424b-9160-2442bc4d6e58/</guid><pubDate>Sat, 22 Jul 2023 00:00:00 GMT</pubDate><description>Confirmed vulnerable driver from Microsoft Block List</description></item><item><title>bs_hwmio64.sys</title><link>https://www.loldrivers.io/drivers/9c4e2e75-a8be-4d2f-b016-e2a98281c8ec/</link><guid>https://www.loldrivers.io/drivers/9c4e2e75-a8be-4d2f-b016-e2a98281c8ec/</guid><pubDate>Sat, 22 Jul 2023 00:00:00 GMT</pubDate><description>Confirmed vulnerable driver from Microsoft Block List</description></item><item><title>bs_rcio64.sys</title><link>https://www.loldrivers.io/drivers/cacf18a5-6d7d-4a63-92d4-bda386a3da18/</link><guid>https://www.loldrivers.io/drivers/cacf18a5-6d7d-4a63-92d4-bda386a3da18/</guid><pubDate>Sat, 22 Jul 2023 00:00:00 GMT</pubDate><description>Confirmed vulnerable driver from Microsoft Block List</description></item><item><title>capcom2.sys</title><link>https://www.loldrivers.io/drivers/45c42e32-6261-43c1-bdbd-cab58da729d8/</link><guid>https://www.loldrivers.io/drivers/45c42e32-6261-43c1-bdbd-cab58da729d8/</guid><pubDate>Sat, 22 Jul 2023 00:00:00 GMT</pubDate><description>Confirmed vulnerable driver from Microsoft Block List</description></item><item><title>directio.sys</title><link>https://www.loldrivers.io/drivers/a2c3f6e9-25a5-4b75-8c6b-ad2d4e155822/</link><guid>https://www.loldrivers.io/drivers/a2c3f6e9-25a5-4b75-8c6b-ad2d4e155822/</guid><pubDate>Sat, 22 Jul 2023 00:00:00 GMT</pubDate><description>Confirmed vulnerable driver from Microsoft Block List</description></item><item><title>directio32_legacy.sys</title><link>https://www.loldrivers.io/drivers/7a0842ca-1a64-4ad1-9d66-25eb983d1742/</link><guid>https://www.loldrivers.io/drivers/7a0842ca-1a64-4ad1-9d66-25eb983d1742/</guid><pubDate>Sat, 22 Jul 2023 00:00:00 GMT</pubDate><description>Confirmed vulnerable driver from Microsoft Block List</description></item><item><title>directio64.sys</title><link>https://www.loldrivers.io/drivers/a254e684-f6eb-40c4-a50a-7b76feb6cc02/</link><guid>https://www.loldrivers.io/drivers/a254e684-f6eb-40c4-a50a-7b76feb6cc02/</guid><pubDate>Sat, 22 Jul 2023 00:00:00 GMT</pubDate><description>PassMark DirectIo64.sys builds through b1008 expose permissively accessible IOCTLs for physical memory, MSRs, PCI configuration space, x86 I/O ports, and kernel or physical-memory dumps. These primitives can support local SYSTEM elevation, kernel tampering, credential exposure, or denial of service. PassMark hardened the driver in b1012.</description></item><item><title>Driver7.sys</title><link>https://www.loldrivers.io/drivers/9ca73d04-3349-4c16-9384-94c43335a031/</link><guid>https://www.loldrivers.io/drivers/9ca73d04-3349-4c16-9384-94c43335a031/</guid><pubDate>Sat, 22 Jul 2023 00:00:00 GMT</pubDate><description>Confirmed vulnerable driver from Microsoft Block List</description></item><item><title>gametersafe.sys</title><link>https://www.loldrivers.io/drivers/1ab1ec8c-1231-4ba4-8804-4a2cda103bb8/</link><guid>https://www.loldrivers.io/drivers/1ab1ec8c-1231-4ba4-8804-4a2cda103bb8/</guid><pubDate>Sat, 22 Jul 2023 00:00:00 GMT</pubDate><description>Confirmed vulnerable driver from Microsoft Block List</description></item><item><title>HWiNFO32.SYS</title><link>https://www.loldrivers.io/drivers/2225128d-a23f-434a-aaee-69a88ea64fbd/</link><guid>https://www.loldrivers.io/drivers/2225128d-a23f-434a-aaee-69a88ea64fbd/</guid><pubDate>Sat, 22 Jul 2023 00:00:00 GMT</pubDate><description>Confirmed vulnerable driver from Microsoft Block List</description></item><item><title>HWiNFO64I.SYS</title><link>https://www.loldrivers.io/drivers/080a834f-3e19-4cae-b940-a4ecf901db28/</link><guid>https://www.loldrivers.io/drivers/080a834f-3e19-4cae-b940-a4ecf901db28/</guid><pubDate>Sat, 22 Jul 2023 00:00:00 GMT</pubDate><description>Confirmed vulnerable driver from Microsoft Block List</description></item><item><title>inpout32.sys</title><link>https://www.loldrivers.io/drivers/97fa88f6-3819-4d56-a82c-52a492a9e2b5/</link><guid>https://www.loldrivers.io/drivers/97fa88f6-3819-4d56-a82c-52a492a9e2b5/</guid><pubDate>Sat, 22 Jul 2023 00:00:00 GMT</pubDate><description>Confirmed vulnerable driver from Microsoft Block List</description></item><item><title>iobitunlocker.sys</title><link>https://www.loldrivers.io/drivers/e368efc7-cf69-47ae-8204-f69dac000b22/</link><guid>https://www.loldrivers.io/drivers/e368efc7-cf69-47ae-8204-f69dac000b22/</guid><pubDate>Sat, 22 Jul 2023 00:00:00 GMT</pubDate><description>Confirmed vulnerable driver from Microsoft Block List</description></item><item><title>jokercontroller.sys</title><link>https://www.loldrivers.io/drivers/4c815256-2534-4476-b15d-7cbf24c80098/</link><guid>https://www.loldrivers.io/drivers/4c815256-2534-4476-b15d-7cbf24c80098/</guid><pubDate>Sat, 22 Jul 2023 00:00:00 GMT</pubDate><description>Confirmed vulnerable driver from Microsoft Block List</description></item><item><title>kdriver.sys</title><link>https://www.loldrivers.io/drivers/51808fa6-89a4-4f4d-aabc-0a7b0e99e34d/</link><guid>https://www.loldrivers.io/drivers/51808fa6-89a4-4f4d-aabc-0a7b0e99e34d/</guid><pubDate>Sat, 22 Jul 2023 00:00:00 GMT</pubDate><description>Confirmed vulnerable driver from Microsoft Block List</description></item><item><title>LgDataCatcher.sys</title><link>https://www.loldrivers.io/drivers/5961e133-ccc3-4530-8f4f-5d975c41028d/</link><guid>https://www.loldrivers.io/drivers/5961e133-ccc3-4530-8f4f-5d975c41028d/</guid><pubDate>Sat, 22 Jul 2023 00:00:00 GMT</pubDate><description>Confirmed vulnerable driver from Microsoft Block List</description></item><item><title>mapmom.sys</title><link>https://www.loldrivers.io/drivers/cf94939a-703f-46a4-917b-d6af7e0685ef/</link><guid>https://www.loldrivers.io/drivers/cf94939a-703f-46a4-917b-d6af7e0685ef/</guid><pubDate>Sat, 22 Jul 2023 00:00:00 GMT</pubDate><description>Confirmed vulnerable driver from Microsoft Block List</description></item><item><title>mhyprotect.sys</title><link>https://www.loldrivers.io/drivers/7abc873d-9c28-44c2-8f60-701a8e26af29/</link><guid>https://www.loldrivers.io/drivers/7abc873d-9c28-44c2-8f60-701a8e26af29/</guid><pubDate>Sat, 22 Jul 2023 00:00:00 GMT</pubDate><description>Confirmed vulnerable driver from Microsoft Block List</description></item><item><title>mhyprotnap.sys</title><link>https://www.loldrivers.io/drivers/75a66604-f024-4f11-8ba7-fdd64a0df3bf/</link><guid>https://www.loldrivers.io/drivers/75a66604-f024-4f11-8ba7-fdd64a0df3bf/</guid><pubDate>Sat, 22 Jul 2023 00:00:00 GMT</pubDate><description>Confirmed vulnerable driver from Microsoft Block List</description></item><item><title>mhyprotrpg.sys</title><link>https://www.loldrivers.io/drivers/181b89e5-4bdd-4e95-b1bc-a294a4adfb29/</link><guid>https://www.loldrivers.io/drivers/181b89e5-4bdd-4e95-b1bc-a294a4adfb29/</guid><pubDate>Sat, 22 Jul 2023 00:00:00 GMT</pubDate><description>Confirmed vulnerable driver from Microsoft Block List</description></item><item><title>mhyprotrpg.Sys</title><link>https://www.loldrivers.io/drivers/ebdde780-e142-44e7-a998-504c516f4695/</link><guid>https://www.loldrivers.io/drivers/ebdde780-e142-44e7-a998-504c516f4695/</guid><pubDate>Sat, 22 Jul 2023 00:00:00 GMT</pubDate><description>Confirmed vulnerable driver from Microsoft Block List</description></item><item><title>mimikatz.sys</title><link>https://www.loldrivers.io/drivers/14556074-b235-4378-b356-f58721629d72/</link><guid>https://www.loldrivers.io/drivers/14556074-b235-4378-b356-f58721629d72/</guid><pubDate>Sat, 22 Jul 2023 00:00:00 GMT</pubDate><description>Confirmed vulnerable driver from Microsoft Block List</description></item><item><title>mlgbbiicaihflrnh.sys</title><link>https://www.loldrivers.io/drivers/b074dcb5-b278-4434-bdd9-14a055d724f3/</link><guid>https://www.loldrivers.io/drivers/b074dcb5-b278-4434-bdd9-14a055d724f3/</guid><pubDate>Sat, 22 Jul 2023 00:00:00 GMT</pubDate><description>Confirmed vulnerable driver from Microsoft Block List</description></item><item><title>msio32.sys</title><link>https://www.loldrivers.io/drivers/58509acb-50b4-41a0-9de3-76c571a459e3/</link><guid>https://www.loldrivers.io/drivers/58509acb-50b4-41a0-9de3-76c571a459e3/</guid><pubDate>Sat, 22 Jul 2023 00:00:00 GMT</pubDate><description>Confirmed vulnerable driver from Microsoft Block List</description></item><item><title>Netfilter.sys</title><link>https://www.loldrivers.io/drivers/9454a752-233e-4ba2-b585-8da242bf8f31/</link><guid>https://www.loldrivers.io/drivers/9454a752-233e-4ba2-b585-8da242bf8f31/</guid><pubDate>Sat, 22 Jul 2023 00:00:00 GMT</pubDate><description>Confirmed vulnerable driver from Microsoft Block List</description></item><item><title>netfilter2.sys</title><link>https://www.loldrivers.io/drivers/5ad8a3b6-6d20-4c95-8fa7-9a507167ba3c/</link><guid>https://www.loldrivers.io/drivers/5ad8a3b6-6d20-4c95-8fa7-9a507167ba3c/</guid><pubDate>Sat, 22 Jul 2023 00:00:00 GMT</pubDate><description>Confirmed vulnerable driver from Microsoft Block List</description></item><item><title>netflt.sys</title><link>https://www.loldrivers.io/drivers/35a9afeb-18f1-4c02-a3aa-830e300138ae/</link><guid>https://www.loldrivers.io/drivers/35a9afeb-18f1-4c02-a3aa-830e300138ae/</guid><pubDate>Sat, 22 Jul 2023 00:00:00 GMT</pubDate><description>Confirmed vulnerable driver from Microsoft Block List</description></item><item><title>NICM.sys</title><link>https://www.loldrivers.io/drivers/0f8e317e-ad2b-4b02-9f96-603bb8d28604/</link><guid>https://www.loldrivers.io/drivers/0f8e317e-ad2b-4b02-9f96-603bb8d28604/</guid><pubDate>Sat, 22 Jul 2023 00:00:00 GMT</pubDate><description>Confirmed vulnerable driver from Microsoft Block List</description></item><item><title>nvflash.sys</title><link>https://www.loldrivers.io/drivers/2a6a38ca-f2e6-456e-9ccf-db59d8c80c9e/</link><guid>https://www.loldrivers.io/drivers/2a6a38ca-f2e6-456e-9ccf-db59d8c80c9e/</guid><pubDate>Sat, 22 Jul 2023 00:00:00 GMT</pubDate><description>Confirmed vulnerable driver from Microsoft Block List</description></item><item><title>nvflsh32.sys</title><link>https://www.loldrivers.io/drivers/c33648d7-6473-4e2b-92f6-93f195bc183f/</link><guid>https://www.loldrivers.io/drivers/c33648d7-6473-4e2b-92f6-93f195bc183f/</guid><pubDate>Sat, 22 Jul 2023 00:00:00 GMT</pubDate><description>Confirmed vulnerable driver from Microsoft Block List</description></item><item><title>pchunter.sys</title><link>https://www.loldrivers.io/drivers/73290fcb-a0d7-481e-81a5-65a9859b50f5/</link><guid>https://www.loldrivers.io/drivers/73290fcb-a0d7-481e-81a5-65a9859b50f5/</guid><pubDate>Sat, 22 Jul 2023 00:00:00 GMT</pubDate><description>Confirmed vulnerable driver from Microsoft Block List</description></item><item><title>phydmaccx64.sys</title><link>https://www.loldrivers.io/drivers/96c8fe71-3acc-41bc-9402-ebd69a961d74/</link><guid>https://www.loldrivers.io/drivers/96c8fe71-3acc-41bc-9402-ebd69a961d74/</guid><pubDate>Sat, 22 Jul 2023 00:00:00 GMT</pubDate><description>Confirmed vulnerable driver from Microsoft Block List</description></item><item><title>phydmaccx86.sys</title><link>https://www.loldrivers.io/drivers/1055625b-3480-48b3-9556-8628a745d8f0/</link><guid>https://www.loldrivers.io/drivers/1055625b-3480-48b3-9556-8628a745d8f0/</guid><pubDate>Sat, 22 Jul 2023 00:00:00 GMT</pubDate><description>Confirmed vulnerable driver from Microsoft Block List</description></item><item><title>ProxyDrv.sys</title><link>https://www.loldrivers.io/drivers/0e3b0052-18c7-4c8b-a064-a1332df07af2/</link><guid>https://www.loldrivers.io/drivers/0e3b0052-18c7-4c8b-a064-a1332df07af2/</guid><pubDate>Sat, 22 Jul 2023 00:00:00 GMT</pubDate><description>Confirmed vulnerable driver from Microsoft Block List</description></item><item><title>rtcoremini64.sys</title><link>https://www.loldrivers.io/drivers/b9e01a11-6395-4837-a202-0c777d717a43/</link><guid>https://www.loldrivers.io/drivers/b9e01a11-6395-4837-a202-0c777d717a43/</guid><pubDate>Sat, 22 Jul 2023 00:00:00 GMT</pubDate><description>Confirmed vulnerable driver from Microsoft Block List</description></item><item><title>rtkiow8x64.sys</title><link>https://www.loldrivers.io/drivers/998ed67c-9c20-46ef-a6ba-abc606b540b9/</link><guid>https://www.loldrivers.io/drivers/998ed67c-9c20-46ef-a6ba-abc606b540b9/</guid><pubDate>Sat, 22 Jul 2023 00:00:00 GMT</pubDate><description>Confirmed vulnerable driver from Microsoft Block List</description></item><item><title>sfdrvx32.sys</title><link>https://www.loldrivers.io/drivers/6c0c60f0-895d-428a-a8ae-e10390bceb12/</link><guid>https://www.loldrivers.io/drivers/6c0c60f0-895d-428a-a8ae-e10390bceb12/</guid><pubDate>Sat, 22 Jul 2023 00:00:00 GMT</pubDate><description>Confirmed vulnerable driver from Microsoft Block List</description></item><item><title>sfdrvx64.sys</title><link>https://www.loldrivers.io/drivers/5a03dc5a-115d-4d6f-b5b5-685f4c014a69/</link><guid>https://www.loldrivers.io/drivers/5a03dc5a-115d-4d6f-b5b5-685f4c014a69/</guid><pubDate>Sat, 22 Jul 2023 00:00:00 GMT</pubDate><description>Confirmed vulnerable driver from Microsoft Block List</description></item><item><title>skill.sys</title><link>https://www.loldrivers.io/drivers/724d7989-dfce-4bb2-9beb-dee15df5b790/</link><guid>https://www.loldrivers.io/drivers/724d7989-dfce-4bb2-9beb-dee15df5b790/</guid><pubDate>Sat, 22 Jul 2023 00:00:00 GMT</pubDate><description>Confirmed vulnerable driver from Microsoft Block List</description></item><item><title>spf.sys</title><link>https://www.loldrivers.io/drivers/56b320b3-5b12-4ec6-81e2-5a16c56c7478/</link><guid>https://www.loldrivers.io/drivers/56b320b3-5b12-4ec6-81e2-5a16c56c7478/</guid><pubDate>Sat, 22 Jul 2023 00:00:00 GMT</pubDate><description>Confirmed vulnerable driver from Microsoft Block List</description></item><item><title>test2.sys</title><link>https://www.loldrivers.io/drivers/6356d7d9-3b82-4731-9d5f-cc9bc37558fc/</link><guid>https://www.loldrivers.io/drivers/6356d7d9-3b82-4731-9d5f-cc9bc37558fc/</guid><pubDate>Sat, 22 Jul 2023 00:00:00 GMT</pubDate><description>Confirmed vulnerable driver from Microsoft Block List</description></item><item><title>tfbfs3ped.sys</title><link>https://www.loldrivers.io/drivers/500e07cb-77c6-4e83-ae3f-73f70f1c10b5/</link><guid>https://www.loldrivers.io/drivers/500e07cb-77c6-4e83-ae3f-73f70f1c10b5/</guid><pubDate>Sat, 22 Jul 2023 00:00:00 GMT</pubDate><description>Confirmed vulnerable driver from Microsoft Block List</description></item><item><title>titidrv.sys</title><link>https://www.loldrivers.io/drivers/705facba-b595-41dd-86a6-93aefe6a6234/</link><guid>https://www.loldrivers.io/drivers/705facba-b595-41dd-86a6-93aefe6a6234/</guid><pubDate>Sat, 22 Jul 2023 00:00:00 GMT</pubDate><description>Confirmed vulnerable driver from Microsoft Block List</description></item><item><title>Tmel.sys</title><link>https://www.loldrivers.io/drivers/1aeb1205-8b02-42b6-a563-b953ea337c19/</link><guid>https://www.loldrivers.io/drivers/1aeb1205-8b02-42b6-a563-b953ea337c19/</guid><pubDate>Sat, 22 Jul 2023 00:00:00 GMT</pubDate><description>Confirmed vulnerable driver from Microsoft Block List</description></item><item><title>vboxguest.sys</title><link>https://www.loldrivers.io/drivers/0baa833c-e4e1-449e-86ee-cafeb11f5fd5/</link><guid>https://www.loldrivers.io/drivers/0baa833c-e4e1-449e-86ee-cafeb11f5fd5/</guid><pubDate>Sat, 22 Jul 2023 00:00:00 GMT</pubDate><description>Confirmed vulnerable driver from Microsoft Block List</description></item><item><title>VBoxMouseNT.sys</title><link>https://www.loldrivers.io/drivers/ecabc507-2cc7-4011-89ab-7d9d659e6f88/</link><guid>https://www.loldrivers.io/drivers/ecabc507-2cc7-4011-89ab-7d9d659e6f88/</guid><pubDate>Sat, 22 Jul 2023 00:00:00 GMT</pubDate><description>Confirmed vulnerable driver from Microsoft Block List</description></item><item><title>VBoxTAP.sys</title><link>https://www.loldrivers.io/drivers/f22e7230-5f32-4c4e-bc9d-9076ebf10baa/</link><guid>https://www.loldrivers.io/drivers/f22e7230-5f32-4c4e-bc9d-9076ebf10baa/</guid><pubDate>Sat, 22 Jul 2023 00:00:00 GMT</pubDate><description>Confirmed vulnerable driver from Microsoft Block List</description></item><item><title>VBoxUSB.Sys</title><link>https://www.loldrivers.io/drivers/70fa8606-c147-4c40-8b7a-980290075327/</link><guid>https://www.loldrivers.io/drivers/70fa8606-c147-4c40-8b7a-980290075327/</guid><pubDate>Sat, 22 Jul 2023 00:00:00 GMT</pubDate><description>Confirmed vulnerable driver from Microsoft Block List</description></item><item><title>VBoxUSBMon.sys</title><link>https://www.loldrivers.io/drivers/babe348d-f160-41ec-9db9-2413b989c1f0/</link><guid>https://www.loldrivers.io/drivers/babe348d-f160-41ec-9db9-2413b989c1f0/</guid><pubDate>Sat, 22 Jul 2023 00:00:00 GMT</pubDate><description>Confirmed vulnerable driver from Microsoft Block List</description></item><item><title>xjokercontroller.sys</title><link>https://www.loldrivers.io/drivers/b3fd8560-79d3-40b7-b05f-c78044176c8c/</link><guid>https://www.loldrivers.io/drivers/b3fd8560-79d3-40b7-b05f-c78044176c8c/</guid><pubDate>Sat, 22 Jul 2023 00:00:00 GMT</pubDate><description>Confirmed vulnerable driver from Microsoft Block List</description></item><item><title>yyprotect64.sys</title><link>https://www.loldrivers.io/drivers/12ccd18a-11da-495a-b4b4-98a2f2bff180/</link><guid>https://www.loldrivers.io/drivers/12ccd18a-11da-495a-b4b4-98a2f2bff180/</guid><pubDate>Sat, 22 Jul 2023 00:00:00 GMT</pubDate><description>Confirmed vulnerable driver from Microsoft Block List</description></item><item><title>echo_driver.sys</title><link>https://www.loldrivers.io/drivers/afb8bb46-1d13-407d-9866-1daa7c82ca63/</link><guid>https://www.loldrivers.io/drivers/afb8bb46-1d13-407d-9866-1daa7c82ca63/</guid><pubDate>Fri, 14 Jul 2023 00:00:00 GMT</pubDate><description>Bad access controls in Inspect Element Ltd.&apos;s echo_driver.sys allows attacker to gain arbitrary memory read and write, which allows for easy Privilege Escalation via Token Theft.</description></item><item><title>834761775.sys</title><link>https://www.loldrivers.io/drivers/66813e1f-13c8-4884-931a-62b46350c345/</link><guid>https://www.loldrivers.io/drivers/66813e1f-13c8-4884-931a-62b46350c345/</guid><pubDate>Wed, 12 Jul 2023 00:00:00 GMT</pubDate><description>Cisco Talos has identified multiple versions of an undocumented malicious driver named “RedDriver,” a driver-based browser hijacker that uses the Windows Filtering Platform (WFP) to intercept browser traffic. RedDriver has been active since at least 2021.
RedDriver utilizes HookSignTool to forge its signature timestamp to bypass Windows driver-signing policies.
Code from multiple open-source tools has been used in the development of RedDriver&apos;s infection chain, including HP-Socket and a custom implementation of ReflectiveLoader.
The authors of RedDriver appear to be skilled in driver development and have deep knowledge of the Windows operating system.
This threat appears to target native Chinese speakers, as it searches for Chinese language browsers to hijack. Additionally, the authors are likely Chinese speakers themselves.</description></item><item><title>ktmutil7ODM.sys</title><link>https://www.loldrivers.io/drivers/809e7c77-f0fa-46fb-862c-71969ae0c032/</link><guid>https://www.loldrivers.io/drivers/809e7c77-f0fa-46fb-862c-71969ae0c032/</guid><pubDate>Wed, 12 Jul 2023 00:00:00 GMT</pubDate><description>Cisco Talos has identified multiple versions of an undocumented malicious driver named “RedDriver,” a driver-based browser hijacker that uses the Windows Filtering Platform (WFP) to intercept browser traffic. RedDriver has been active since at least 2021.
RedDriver utilizes HookSignTool to forge its signature timestamp to bypass Windows driver-signing policies.
Code from multiple open-source tools has been used in the development of RedDriver&apos;s infection chain, including HP-Socket and a custom implementation of ReflectiveLoader.
The authors of RedDriver appear to be skilled in driver development and have deep knowledge of the Windows operating system.
This threat appears to target native Chinese speakers, as it searches for Chinese language browsers to hijack. Additionally, the authors are likely Chinese speakers themselves.</description></item><item><title>NlsLexicons0024UvN.sys</title><link>https://www.loldrivers.io/drivers/18a842be-681a-4f32-97fd-57cb72ff5f3a/</link><guid>https://www.loldrivers.io/drivers/18a842be-681a-4f32-97fd-57cb72ff5f3a/</guid><pubDate>Wed, 12 Jul 2023 00:00:00 GMT</pubDate><description>Cisco Talos has identified multiple versions of an undocumented malicious driver named “RedDriver,” a driver-based browser hijacker that uses the Windows Filtering Platform (WFP) to intercept browser traffic. RedDriver has been active since at least 2021.
RedDriver utilizes HookSignTool to forge its signature timestamp to bypass Windows driver-signing policies.
Code from multiple open-source tools has been used in the development of RedDriver&apos;s infection chain, including HP-Socket and a custom implementation of ReflectiveLoader.
The authors of RedDriver appear to be skilled in driver development and have deep knowledge of the Windows operating system.
This threat appears to target native Chinese speakers, as it searches for Chinese language browsers to hijack. Additionally, the authors are likely Chinese speakers themselves.</description></item><item><title>reddriver.sys</title><link>https://www.loldrivers.io/drivers/87593c63-9e3e-4d09-aa47-94bca0783396/</link><guid>https://www.loldrivers.io/drivers/87593c63-9e3e-4d09-aa47-94bca0783396/</guid><pubDate>Wed, 12 Jul 2023 00:00:00 GMT</pubDate><description>Cisco Talos has identified multiple versions of an undocumented malicious driver named “RedDriver,” a driver-based browser hijacker that uses the Windows Filtering Platform (WFP) to intercept browser traffic. RedDriver has been active since at least 2021.
RedDriver utilizes HookSignTool to forge its signature timestamp to bypass Windows driver-signing policies.
Code from multiple open-source tools has been used in the development of RedDriver&apos;s infection chain, including HP-Socket and a custom implementation of ReflectiveLoader.
The authors of RedDriver appear to be skilled in driver development and have deep knowledge of the Windows operating system.
This threat appears to target native Chinese speakers, as it searches for Chinese language browsers to hijack. Additionally, the authors are likely Chinese speakers themselves.</description></item><item><title>spwizimgVT.sys</title><link>https://www.loldrivers.io/drivers/b759adfa-b353-4ca3-9dfb-8fadf7a437eb/</link><guid>https://www.loldrivers.io/drivers/b759adfa-b353-4ca3-9dfb-8fadf7a437eb/</guid><pubDate>Wed, 12 Jul 2023 00:00:00 GMT</pubDate><description>Cisco Talos has identified multiple versions of an undocumented malicious driver named “RedDriver,” a driver-based browser hijacker that uses the Windows Filtering Platform (WFP) to intercept browser traffic. RedDriver has been active since at least 2021.
RedDriver utilizes HookSignTool to forge its signature timestamp to bypass Windows driver-signing policies.
Code from multiple open-source tools has been used in the development of RedDriver&apos;s infection chain, including HP-Socket and a custom implementation of ReflectiveLoader.
The authors of RedDriver appear to be skilled in driver development and have deep knowledge of the Windows operating system.
This threat appears to target native Chinese speakers, as it searches for Chinese language browsers to hijack. Additionally, the authors are likely Chinese speakers themselves.</description></item><item><title>typelibdE.sys</title><link>https://www.loldrivers.io/drivers/9713603a-53bf-4907-a304-b422db741fc6/</link><guid>https://www.loldrivers.io/drivers/9713603a-53bf-4907-a304-b422db741fc6/</guid><pubDate>Wed, 12 Jul 2023 00:00:00 GMT</pubDate><description>Cisco Talos has identified multiple versions of an undocumented malicious driver named “RedDriver,” a driver-based browser hijacker that uses the Windows Filtering Platform (WFP) to intercept browser traffic. RedDriver has been active since at least 2021.
RedDriver utilizes HookSignTool to forge its signature timestamp to bypass Windows driver-signing policies.
Code from multiple open-source tools has been used in the development of RedDriver&apos;s infection chain, including HP-Socket and a custom implementation of ReflectiveLoader.
The authors of RedDriver appear to be skilled in driver development and have deep knowledge of the Windows operating system.
This threat appears to target native Chinese speakers, as it searches for Chinese language browsers to hijack. Additionally, the authors are likely Chinese speakers themselves.</description></item><item><title>telephonuAfY.sys</title><link>https://www.loldrivers.io/drivers/0d039ee9-aaa5-49c2-a980-405d4290ee0a/</link><guid>https://www.loldrivers.io/drivers/0d039ee9-aaa5-49c2-a980-405d4290ee0a/</guid><pubDate>Tue, 11 Jul 2023 00:00:00 GMT</pubDate><description>Cisco Talos has identified multiple versions of an undocumented malicious driver named “RedDriver,” a driver-based browser hijacker that uses the Windows Filtering Platform (WFP) to intercept browser traffic. RedDriver has been active since at least 2021.
RedDriver utilizes HookSignTool to forge its signature timestamp to bypass Windows driver-signing policies.
Code from multiple open-source tools has been used in the development of RedDriver&apos;s infection chain, including HP-Socket and a custom implementation of ReflectiveLoader.
The authors of RedDriver appear to be skilled in driver development and have deep knowledge of the Windows operating system.
This threat appears to target native Chinese speakers, as it searches for Chinese language browsers to hijack. Additionally, the authors are likely Chinese speakers themselves.</description></item><item><title>Chaos-Rootkit.sys</title><link>https://www.loldrivers.io/drivers/abcd2c10-1078-4cf9-b320-04ca38d22f98/</link><guid>https://www.loldrivers.io/drivers/abcd2c10-1078-4cf9-b320-04ca38d22f98/</guid><pubDate>Mon, 05 Jun 2023 00:00:00 GMT</pubDate><description>Chaos-Rootkit is a x64 ring0 rootkit with process hiding, privilege escalation, and capabilities for protecting and unprotecting processes, work on the latest Windows versions.</description></item><item><title>fgme.sys</title><link>https://www.loldrivers.io/drivers/d3111e83-52eb-4a8c-817d-761ea72d37e2/</link><guid>https://www.loldrivers.io/drivers/d3111e83-52eb-4a8c-817d-761ea72d37e2/</guid><pubDate>Mon, 05 Jun 2023 00:00:00 GMT</pubDate><description>BlackCat Ransomware Deploys New Signed Kernel Driver. BlackCat ransomware incident that occurred in February 2023.</description></item><item><title>kt2.sys</title><link>https://www.loldrivers.io/drivers/833fc08f-217d-4d3f-8c8e-782c61120407/</link><guid>https://www.loldrivers.io/drivers/833fc08f-217d-4d3f-8c8e-782c61120407/</guid><pubDate>Mon, 05 Jun 2023 00:00:00 GMT</pubDate><description>BlackCat Ransomware Deploys New Signed Kernel Driver. BlackCat ransomware incident that occurred in February 2023.</description></item><item><title>ktes.sys</title><link>https://www.loldrivers.io/drivers/c734bcff-aaaa-4450-a9a9-25ee52aa7ff1/</link><guid>https://www.loldrivers.io/drivers/c734bcff-aaaa-4450-a9a9-25ee52aa7ff1/</guid><pubDate>Mon, 05 Jun 2023 00:00:00 GMT</pubDate><description>BlackCat Ransomware Deploys New Signed Kernel Driver. BlackCat ransomware incident that occurred in February 2023.</description></item><item><title>ktgn.sys</title><link>https://www.loldrivers.io/drivers/3ea63674-2599-43b5-9390-4a929ec99f48/</link><guid>https://www.loldrivers.io/drivers/3ea63674-2599-43b5-9390-4a929ec99f48/</guid><pubDate>Mon, 05 Jun 2023 00:00:00 GMT</pubDate><description>BlackCat Ransomware Deploys New Signed Kernel Driver. BlackCat ransomware incident that occurred in February 2023.</description></item><item><title>malicious.sys</title><link>https://www.loldrivers.io/drivers/3e5c0fc4-bfe8-4af2-9613-4f56b0e3c2c8/</link><guid>https://www.loldrivers.io/drivers/3e5c0fc4-bfe8-4af2-9613-4f56b0e3c2c8/</guid><pubDate>Mon, 05 Jun 2023 00:00:00 GMT</pubDate><description>This demo is a presentation at the CYBERSEC 2023 in Taiwan. The presentation showcases the abuse of RTCore64.sys (CVE-2019-16098) from MSI and the nullification of the DSE flag to load a malicious unsigned driver. The presentation also demonstrates an attack on 360 Total Security by nulling out its ObRegisterCallbacks and notify callbacks, enabling the execution of any malicious behavior on the processes of 360 Total Security.</description></item><item><title>MSqPq.sys</title><link>https://www.loldrivers.io/drivers/8198f5af-4b40-4800-a22a-4a7cf957ef37/</link><guid>https://www.loldrivers.io/drivers/8198f5af-4b40-4800-a22a-4a7cf957ef37/</guid><pubDate>Mon, 05 Jun 2023 00:00:00 GMT</pubDate><description>BlackCat Ransomware Deploys New Signed Kernel Driver. BlackCat ransomware incident that occurred in February 2023.</description></item><item><title>NQrmq.sys</title><link>https://www.loldrivers.io/drivers/61abe019-08cb-48a3-89b2-62810696f277/</link><guid>https://www.loldrivers.io/drivers/61abe019-08cb-48a3-89b2-62810696f277/</guid><pubDate>Mon, 05 Jun 2023 00:00:00 GMT</pubDate><description>Found via RichPEHeaderHash pivoting.</description></item><item><title>wfshbr64.sys</title><link>https://www.loldrivers.io/drivers/ddf661c0-7dfc-4c26-89c5-00cd6a81a139/</link><guid>https://www.loldrivers.io/drivers/ddf661c0-7dfc-4c26-89c5-00cd6a81a139/</guid><pubDate>Mon, 05 Jun 2023 00:00:00 GMT</pubDate><description>wfshbr64.sys and wfshbr32.sys specially crafted payload allows arbitrary user to perform bitwise operation with arbitrary EPROCESS offset and flags value to purposely elevate the game process to CodeGen Full protection by manipulating EPROCESS.Protection and EPROCESS.SignatureLevel flags (security hole as a feature).

The driver is signed by Microsoft hardware compatibility publisher that is submitted via Microsoft Hardware Program.</description></item><item><title>WinTapix.sys</title><link>https://www.loldrivers.io/drivers/93740202-930c-4ab4-8603-8ec9532c5415/</link><guid>https://www.loldrivers.io/drivers/93740202-930c-4ab4-8603-8ec9532c5415/</guid><pubDate>Mon, 05 Jun 2023 00:00:00 GMT</pubDate><description>Wintapix.sys is partially protected by VMProtect, a software protection tool that uses virtualization to protect software applications from reverse engineering and unauthorized usage. It transforms the original executable file into a virtualized code executed in a protected environment, making it difficult to analyze and tamper with.</description></item><item><title>amsdk.sys</title><link>https://www.loldrivers.io/drivers/a285591e-ad3c-46a3-a648-c58589ff5efc/</link><guid>https://www.loldrivers.io/drivers/a285591e-ad3c-46a3-a648-c58589ff5efc/</guid><pubDate>Mon, 22 May 2023 00:00:00 GMT</pubDate><description>Vulnerable driver found in https://github.com/hfiref0x/KDU.</description></item><item><title>CtiIo64.sys</title><link>https://www.loldrivers.io/drivers/de365e80-45cb-48fb-af6e-0a96a5ad7777/</link><guid>https://www.loldrivers.io/drivers/de365e80-45cb-48fb-af6e-0a96a5ad7777/</guid><pubDate>Mon, 22 May 2023 00:00:00 GMT</pubDate><description>The driver is part of Dragon Center (or MSI Center?) from MSI. It creates \Device\CtiIo ACLless DO and provides access to memory and IO. The driver is signed with WHQL cert.</description></item><item><title>dkrTK.sys</title><link>https://www.loldrivers.io/drivers/8a162702-b043-4108-bb6c-1488751a4a32/</link><guid>https://www.loldrivers.io/drivers/8a162702-b043-4108-bb6c-1488751a4a32/</guid><pubDate>Mon, 22 May 2023 00:00:00 GMT</pubDate><description>The User Agent tjr.exe, which is protected via a virtual machine, drops the kernel driver to the user temporary directory C:\%User%\AppData\Local\Temp\Ktgn.sys. It then installs the dropped driver with the name ktgn and the start value = System (to start when the system restarts). From our analysis of what occurs when a user interfaces with this driver, we observed that it only uses one of the exposed Device Input and Output Control (IOCTL) code — Kill Process, which is used to kill security agent processes installed on the system.</description></item><item><title>gmer64.sys</title><link>https://www.loldrivers.io/drivers/7ce8fb06-46eb-4f4f-90d5-5518a6561f15/</link><guid>https://www.loldrivers.io/drivers/7ce8fb06-46eb-4f4f-90d5-5518a6561f15/</guid><pubDate>Mon, 22 May 2023 00:00:00 GMT</pubDate><description>Driver used by the GMER application. Which is an application that detects and removes rootkits</description></item><item><title>mimidrv.sys</title><link>https://www.loldrivers.io/drivers/87752fb8-e9f6-4235-91e2-c4343677d817/</link><guid>https://www.loldrivers.io/drivers/87752fb8-e9f6-4235-91e2-c4343677d817/</guid><pubDate>Mon, 22 May 2023 00:00:00 GMT</pubDate><description>Mimidrv is a signed Windows Driver Model WDM kernel mode software driver meant to be used with the standard Mimikatz executable.</description></item><item><title>SysDrv3S.sys</title><link>https://www.loldrivers.io/drivers/cf49f43c-d7b4-4c1a-a40d-1be36ea64bff/</link><guid>https://www.loldrivers.io/drivers/cf49f43c-d7b4-4c1a-a40d-1be36ea64bff/</guid><pubDate>Mon, 22 May 2023 00:00:00 GMT</pubDate><description>Vulnerable driver found in https://github.com/hfiref0x/KDU.</description></item><item><title>EIO.sys</title><link>https://www.loldrivers.io/drivers/f654ad84-c61d-477c-a0b2-d153b927dfcc/</link><guid>https://www.loldrivers.io/drivers/f654ad84-c61d-477c-a0b2-d153b927dfcc/</guid><pubDate>Sat, 20 May 2023 00:00:00 GMT</pubDate><description>This is a vulnerable driver per Microsoft.</description></item><item><title>windbg.sys</title><link>https://www.loldrivers.io/drivers/da7314dc-6cf1-4d74-a0d1-796fc08944f8/</link><guid>https://www.loldrivers.io/drivers/da7314dc-6cf1-4d74-a0d1-796fc08944f8/</guid><pubDate>Sat, 20 May 2023 00:00:00 GMT</pubDate><description>These samples are related to CopperStealth campaign found by TrendMicro. CopperStealth’s infection chain involves dropping and loading a rootkit, which later injects its payload into explorer.exe and another system process. These payloads are responsible for downloading and running additional tasks. The rootkit also blocks access to blocklisted registry keys and prevents certain executables and drivers from running.</description></item><item><title>KfeCo10X64.sys</title><link>https://www.loldrivers.io/drivers/3e0bf6dc-791b-4170-8c40-427e7299d93d/</link><guid>https://www.loldrivers.io/drivers/3e0bf6dc-791b-4170-8c40-427e7299d93d/</guid><pubDate>Fri, 12 May 2023 00:00:00 GMT</pubDate><description>Killer exposes COM interfaces that allow non-privileged users 1) to block network for any process 2) to manage any service in the OS. Killer is preinstalled to laptops equipped with Intel Killer NICs (e.g. Dell). Since Intel patched the vulnerability quietly, it&apos;s not clear which version is safe. Also, it is unclear which OEMs are affected. Dell is definitely in the list, but it is likely that other vendors with Killer NICs on board, such as Acer and MSI, are affected too. Some users think that Killer suite is required for the NIC to work properly, so they install it even after a fresh Windows install. This version is confirmed vulnerable based on the script usage from zwclose.</description></item><item><title>KfeCo11X64.sys</title><link>https://www.loldrivers.io/drivers/76b5dfae-b384-45ce-8646-b2eec6b76a1e/</link><guid>https://www.loldrivers.io/drivers/76b5dfae-b384-45ce-8646-b2eec6b76a1e/</guid><pubDate>Fri, 12 May 2023 00:00:00 GMT</pubDate><description>Killer exposes COM interfaces that allow non-privileged users 1) to block network for any process 2) to manage any service in the OS. Killer is preinstalled to laptops equipped with Intel Killer NICs (e.g. Dell). Since Intel patched the vulnerability quietly, it&apos;s not clear which version is safe. Also, it is unclear which OEMs are affected. Dell is definitely in the list, but it is likely that other vendors with Killer NICs on board, such as Acer and MSI, are affected too. Some users think that Killer suite is required for the NIC to work properly, so they install it even after a fresh Windows install. This version is confirmed vulnerable based on the script usage from zwclose.</description></item><item><title>etdsupp.sys</title><link>https://www.loldrivers.io/drivers/0e8da43d-92e0-43f9-bc34-50a7d15b34bd/</link><guid>https://www.loldrivers.io/drivers/0e8da43d-92e0-43f9-bc34-50a7d15b34bd/</guid><pubDate>Thu, 11 May 2023 00:00:00 GMT</pubDate><description></description></item><item><title>irec.sys</title><link>https://www.loldrivers.io/drivers/d74fdf19-b4b0-4ec2-9c29-4213b064138b/</link><guid>https://www.loldrivers.io/drivers/d74fdf19-b4b0-4ec2-9c29-4213b064138b/</guid><pubDate>Thu, 11 May 2023 00:00:00 GMT</pubDate><description>The driver in question, identified as \\.\IREC, provides an interface for external programs to directly interact with system processes. Its key functionality is encapsulated in the OPENPROCESS function which, upon receiving a Process ID (PID), returns a handle to that specific process operating within the kernels domain. The vulnerability emerges from the indiscriminate nature of this functionality. An ill-intentioned actor can exploit this to obtain handles to critical processes like LSASS. With a hardcoded access mask of 0x410, this driver essentially grants PROCESS_QUERY_INFORMATION and PROCESS_VM_READ permissions, enabling unauthorized memory dumps from privileged processes, all from an unprivileged context.</description></item><item><title>LMIinfo.sys</title><link>https://www.loldrivers.io/drivers/a02ee964-a21e-4b08-9c98-a730c90bfd53/</link><guid>https://www.loldrivers.io/drivers/a02ee964-a21e-4b08-9c98-a730c90bfd53/</guid><pubDate>Thu, 11 May 2023 00:00:00 GMT</pubDate><description></description></item><item><title>fur.sys</title><link>https://www.loldrivers.io/drivers/c1265ee4-aed4-4e65-ac54-c64deb5e3b28/</link><guid>https://www.loldrivers.io/drivers/c1265ee4-aed4-4e65-ac54-c64deb5e3b28/</guid><pubDate>Sun, 07 May 2023 00:00:00 GMT</pubDate><description>SophosLabs has discovered that threat actors are using a new driver loader called BURNTCIGAR to install a malicious driver signed with Microsoft.</description></item><item><title>mJj0ge.sys</title><link>https://www.loldrivers.io/drivers/412f4aaf-5525-458c-b87e-311e504b856d/</link><guid>https://www.loldrivers.io/drivers/412f4aaf-5525-458c-b87e-311e504b856d/</guid><pubDate>Sun, 07 May 2023 00:00:00 GMT</pubDate><description>The criminals signed their AV-killer malware, closely related to one known as BURNTCIGAR, with a legitimate WHCP certificate</description></item><item><title>prokiller64.sys</title><link>https://www.loldrivers.io/drivers/6fe10a55-7fb8-4a9d-9ebc-1b27b6e5b833/</link><guid>https://www.loldrivers.io/drivers/6fe10a55-7fb8-4a9d-9ebc-1b27b6e5b833/</guid><pubDate>Sun, 07 May 2023 00:00:00 GMT</pubDate><description>Signed POORTRY Samples</description></item><item><title>amigendrv64.sys</title><link>https://www.loldrivers.io/drivers/5c45ae9e-cb6f-4eab-a070-b0187202e080/</link><guid>https://www.loldrivers.io/drivers/5c45ae9e-cb6f-4eab-a070-b0187202e080/</guid><pubDate>Sat, 06 May 2023 00:00:00 GMT</pubDate><description></description></item><item><title>AsUpIO.sys</title><link>https://www.loldrivers.io/drivers/8d97bb7f-e009-4dc7-ab9d-fde293e679dc/</link><guid>https://www.loldrivers.io/drivers/8d97bb7f-e009-4dc7-ab9d-fde293e679dc/</guid><pubDate>Sat, 06 May 2023 00:00:00 GMT</pubDate><description></description></item><item><title>aswArPot.sys</title><link>https://www.loldrivers.io/drivers/043773c5-120a-4c6b-8485-8f1f5c47fd3e/</link><guid>https://www.loldrivers.io/drivers/043773c5-120a-4c6b-8485-8f1f5c47fd3e/</guid><pubDate>Sat, 06 May 2023 00:00:00 GMT</pubDate><description></description></item><item><title>atillk64.sys</title><link>https://www.loldrivers.io/drivers/10b1fc3d-c444-4885-8ca9-4b5891885507/</link><guid>https://www.loldrivers.io/drivers/10b1fc3d-c444-4885-8ca9-4b5891885507/</guid><pubDate>Sat, 06 May 2023 00:00:00 GMT</pubDate><description></description></item><item><title>ATSZIO.sys</title><link>https://www.loldrivers.io/drivers/6ec5ddda-f302-4008-a73e-12814c1d571f/</link><guid>https://www.loldrivers.io/drivers/6ec5ddda-f302-4008-a73e-12814c1d571f/</guid><pubDate>Sat, 06 May 2023 00:00:00 GMT</pubDate><description></description></item><item><title>BS_I2cIo.sys</title><link>https://www.loldrivers.io/drivers/66be9e0a-9246-4404-b5b5-7fbde351668f/</link><guid>https://www.loldrivers.io/drivers/66be9e0a-9246-4404-b5b5-7fbde351668f/</guid><pubDate>Sat, 06 May 2023 00:00:00 GMT</pubDate><description></description></item><item><title>BS_RCIOW1064.sys</title><link>https://www.loldrivers.io/drivers/39f427b6-aad3-4cb8-b363-9113a6d53b07/</link><guid>https://www.loldrivers.io/drivers/39f427b6-aad3-4cb8-b363-9113a6d53b07/</guid><pubDate>Sat, 06 May 2023 00:00:00 GMT</pubDate><description></description></item><item><title>CorsairLLAccess64.sys</title><link>https://www.loldrivers.io/drivers/a9d9cbb7-b5f6-4e74-97a5-29993263280e/</link><guid>https://www.loldrivers.io/drivers/a9d9cbb7-b5f6-4e74-97a5-29993263280e/</guid><pubDate>Sat, 06 May 2023 00:00:00 GMT</pubDate><description>Corsair LL Access 1.0.22.0 maps caller-selected physical addresses with MmMapIoSpace and can expose the mapped pages to user mode through MmMapLockedPagesSpecifyCache. These physical-memory access primitives can be abused for kernel tampering by an attacker able to load and open the driver.</description></item><item><title>cpuz.sys</title><link>https://www.loldrivers.io/drivers/16d8962b-cf96-432f-8a43-d41f06828f56/</link><guid>https://www.loldrivers.io/drivers/16d8962b-cf96-432f-8a43-d41f06828f56/</guid><pubDate>Sat, 06 May 2023 00:00:00 GMT</pubDate><description></description></item><item><title>CupFixerx64.sys</title><link>https://www.loldrivers.io/drivers/c98af16e-197f-4e66-bf94-14646bde32dd/</link><guid>https://www.loldrivers.io/drivers/c98af16e-197f-4e66-bf94-14646bde32dd/</guid><pubDate>Sat, 06 May 2023 00:00:00 GMT</pubDate><description></description></item><item><title>DirectIo.sys</title><link>https://www.loldrivers.io/drivers/62e2a967-1f03-4225-a325-122b109208f3/</link><guid>https://www.loldrivers.io/drivers/62e2a967-1f03-4225-a325-122b109208f3/</guid><pubDate>Sat, 06 May 2023 00:00:00 GMT</pubDate><description></description></item><item><title>DirectIo32.sys</title><link>https://www.loldrivers.io/drivers/ee2d68aa-1a65-4967-8627-73590b041538/</link><guid>https://www.loldrivers.io/drivers/ee2d68aa-1a65-4967-8627-73590b041538/</guid><pubDate>Sat, 06 May 2023 00:00:00 GMT</pubDate><description></description></item><item><title>directio64.sys</title><link>https://www.loldrivers.io/drivers/afed9dff-245e-4875-a156-3c5584beed03/</link><guid>https://www.loldrivers.io/drivers/afed9dff-245e-4875-a156-3c5584beed03/</guid><pubDate>Sat, 06 May 2023 00:00:00 GMT</pubDate><description></description></item><item><title>ElbyCDIO.sys</title><link>https://www.loldrivers.io/drivers/7a722cd5-69ec-4680-9f20-9387f249a891/</link><guid>https://www.loldrivers.io/drivers/7a722cd5-69ec-4680-9f20-9387f249a891/</guid><pubDate>Sat, 06 May 2023 00:00:00 GMT</pubDate><description></description></item><item><title>ene.sys</title><link>https://www.loldrivers.io/drivers/3bec7340-bd8b-43ae-8569-d81a66f01dda/</link><guid>https://www.loldrivers.io/drivers/3bec7340-bd8b-43ae-8569-d81a66f01dda/</guid><pubDate>Sat, 06 May 2023 00:00:00 GMT</pubDate><description></description></item><item><title>eneio64.sys</title><link>https://www.loldrivers.io/drivers/90ecbbf7-b02f-424d-8b7d-56cc9e3b5873/</link><guid>https://www.loldrivers.io/drivers/90ecbbf7-b02f-424d-8b7d-56cc9e3b5873/</guid><pubDate>Sat, 06 May 2023 00:00:00 GMT</pubDate><description></description></item><item><title>gdrv.sys</title><link>https://www.loldrivers.io/drivers/613b8509-18c0-4720-b489-736776b6713e/</link><guid>https://www.loldrivers.io/drivers/613b8509-18c0-4720-b489-736776b6713e/</guid><pubDate>Sat, 06 May 2023 00:00:00 GMT</pubDate><description></description></item><item><title>GLCKIO2.sys</title><link>https://www.loldrivers.io/drivers/52ded752-2708-499e-8f37-98e4a9adc23c/</link><guid>https://www.loldrivers.io/drivers/52ded752-2708-499e-8f37-98e4a9adc23c/</guid><pubDate>Sat, 06 May 2023 00:00:00 GMT</pubDate><description></description></item><item><title>gvcidrv64.sys</title><link>https://www.loldrivers.io/drivers/56cdac8e-d87d-49c8-b281-6e096c2390d1/</link><guid>https://www.loldrivers.io/drivers/56cdac8e-d87d-49c8-b281-6e096c2390d1/</guid><pubDate>Sat, 06 May 2023 00:00:00 GMT</pubDate><description></description></item><item><title>HpPortIox64.sys</title><link>https://www.loldrivers.io/drivers/13637210-2e1c-45a4-9f76-fe38c3c34264/</link><guid>https://www.loldrivers.io/drivers/13637210-2e1c-45a4-9f76-fe38c3c34264/</guid><pubDate>Sat, 06 May 2023 00:00:00 GMT</pubDate><description></description></item><item><title>HW.sys</title><link>https://www.loldrivers.io/drivers/2d7c96d3-2d6c-44cd-a8a1-5239f571a24a/</link><guid>https://www.loldrivers.io/drivers/2d7c96d3-2d6c-44cd-a8a1-5239f571a24a/</guid><pubDate>Sat, 06 May 2023 00:00:00 GMT</pubDate><description></description></item><item><title>iQVW64.SYS</title><link>https://www.loldrivers.io/drivers/4dd3289c-522c-4fce-b48e-5370efc90fa1/</link><guid>https://www.loldrivers.io/drivers/4dd3289c-522c-4fce-b48e-5370efc90fa1/</guid><pubDate>Sat, 06 May 2023 00:00:00 GMT</pubDate><description></description></item><item><title>KApcHelper_x64.sys</title><link>https://www.loldrivers.io/drivers/5261cacf-380c-4573-85ff-a643cbdf009a/</link><guid>https://www.loldrivers.io/drivers/5261cacf-380c-4573-85ff-a643cbdf009a/</guid><pubDate>Sat, 06 May 2023 00:00:00 GMT</pubDate><description>Vulnerable driving using the stolen Nvidia Certificate.</description></item><item><title>kEvP64.sys</title><link>https://www.loldrivers.io/drivers/73196456-40ae-4b6d-8562-07cf99458a7d/</link><guid>https://www.loldrivers.io/drivers/73196456-40ae-4b6d-8562-07cf99458a7d/</guid><pubDate>Sat, 06 May 2023 00:00:00 GMT</pubDate><description></description></item><item><title>LHA.sys</title><link>https://www.loldrivers.io/drivers/eb07ef7e-0402-48eb-8e06-8fb76eda5b84/</link><guid>https://www.loldrivers.io/drivers/eb07ef7e-0402-48eb-8e06-8fb76eda5b84/</guid><pubDate>Sat, 06 May 2023 00:00:00 GMT</pubDate><description></description></item><item><title>libnicm.sys</title><link>https://www.loldrivers.io/drivers/a0fbd397-64d5-4af2-844b-b096e08a1866/</link><guid>https://www.loldrivers.io/drivers/a0fbd397-64d5-4af2-844b-b096e08a1866/</guid><pubDate>Sat, 06 May 2023 00:00:00 GMT</pubDate><description></description></item><item><title>MsIo64.sys</title><link>https://www.loldrivers.io/drivers/214654eb-90c4-48c8-a183-0157e50bf07f/</link><guid>https://www.loldrivers.io/drivers/214654eb-90c4-48c8-a183-0157e50bf07f/</guid><pubDate>Sat, 06 May 2023 00:00:00 GMT</pubDate><description></description></item><item><title>NICM.SYS</title><link>https://www.loldrivers.io/drivers/f4126206-564f-49f5-a942-2138a3131e0e/</link><guid>https://www.loldrivers.io/drivers/f4126206-564f-49f5-a942-2138a3131e0e/</guid><pubDate>Sat, 06 May 2023 00:00:00 GMT</pubDate><description></description></item><item><title>nscm.sys</title><link>https://www.loldrivers.io/drivers/90afa27c-0f67-46a6-b4a9-809f55157c71/</link><guid>https://www.loldrivers.io/drivers/90afa27c-0f67-46a6-b4a9-809f55157c71/</guid><pubDate>Sat, 06 May 2023 00:00:00 GMT</pubDate><description></description></item><item><title>NTIOLib.sys</title><link>https://www.loldrivers.io/drivers/7f9842a0-8118-462e-8860-227265ff4379/</link><guid>https://www.loldrivers.io/drivers/7f9842a0-8118-462e-8860-227265ff4379/</guid><pubDate>Sat, 06 May 2023 00:00:00 GMT</pubDate><description></description></item><item><title>procexp.Sys</title><link>https://www.loldrivers.io/drivers/0567c6c4-282f-406f-9369-7f876b899c25/</link><guid>https://www.loldrivers.io/drivers/0567c6c4-282f-406f-9369-7f876b899c25/</guid><pubDate>Sat, 06 May 2023 00:00:00 GMT</pubDate><description></description></item><item><title>RTCore64.sys</title><link>https://www.loldrivers.io/drivers/275c80c5-a67c-4536-b29e-4e481242cb01/</link><guid>https://www.loldrivers.io/drivers/275c80c5-a67c-4536-b29e-4e481242cb01/</guid><pubDate>Sat, 06 May 2023 00:00:00 GMT</pubDate><description></description></item><item><title>RwDrv.sys</title><link>https://www.loldrivers.io/drivers/b03798af-d25a-400b-9236-4643a802846f/</link><guid>https://www.loldrivers.io/drivers/b03798af-d25a-400b-9236-4643a802846f/</guid><pubDate>Sat, 06 May 2023 00:00:00 GMT</pubDate><description></description></item><item><title>SANDRA.sys</title><link>https://www.loldrivers.io/drivers/a7628504-9e35-4e42-91f7-0c0a512549f4/</link><guid>https://www.loldrivers.io/drivers/a7628504-9e35-4e42-91f7-0c0a512549f4/</guid><pubDate>Sat, 06 May 2023 00:00:00 GMT</pubDate><description></description></item><item><title>sfdrvx32.sys</title><link>https://www.loldrivers.io/drivers/2ada18ae-2c52-49b6-b1a0-cf3b267f6dc7/</link><guid>https://www.loldrivers.io/drivers/2ada18ae-2c52-49b6-b1a0-cf3b267f6dc7/</guid><pubDate>Sat, 06 May 2023 00:00:00 GMT</pubDate><description></description></item><item><title>TmComm.sys</title><link>https://www.loldrivers.io/drivers/d35cb48d-2aca-4d7d-a194-f4566183bcd9/</link><guid>https://www.loldrivers.io/drivers/d35cb48d-2aca-4d7d-a194-f4566183bcd9/</guid><pubDate>Sat, 06 May 2023 00:00:00 GMT</pubDate><description></description></item><item><title>VBoxDrv.sys</title><link>https://www.loldrivers.io/drivers/79542852-3a0c-43bc-bfa3-3eeb0e1d7fd2/</link><guid>https://www.loldrivers.io/drivers/79542852-3a0c-43bc-bfa3-3eeb0e1d7fd2/</guid><pubDate>Sat, 06 May 2023 00:00:00 GMT</pubDate><description></description></item><item><title>VBoxUSB.Sys</title><link>https://www.loldrivers.io/drivers/5938df1d-9513-449f-8252-c442ddca0c2a/</link><guid>https://www.loldrivers.io/drivers/5938df1d-9513-449f-8252-c442ddca0c2a/</guid><pubDate>Sat, 06 May 2023 00:00:00 GMT</pubDate><description></description></item><item><title>viragt64.sys</title><link>https://www.loldrivers.io/drivers/7edb5602-239f-460a-89d6-363ff1059765/</link><guid>https://www.loldrivers.io/drivers/7edb5602-239f-460a-89d6-363ff1059765/</guid><pubDate>Sat, 06 May 2023 00:00:00 GMT</pubDate><description></description></item><item><title>vmdrv.sys</title><link>https://www.loldrivers.io/drivers/2ea12acc-95b6-4f91-afb7-8ded7a2fe9d9/</link><guid>https://www.loldrivers.io/drivers/2ea12acc-95b6-4f91-afb7-8ded7a2fe9d9/</guid><pubDate>Sat, 06 May 2023 00:00:00 GMT</pubDate><description></description></item><item><title>WinFlash64.sys</title><link>https://www.loldrivers.io/drivers/7b893f79-b5b0-4373-9d29-c53a21fe6fc3/</link><guid>https://www.loldrivers.io/drivers/7b893f79-b5b0-4373-9d29-c53a21fe6fc3/</guid><pubDate>Sat, 06 May 2023 00:00:00 GMT</pubDate><description></description></item><item><title>winio64.sys</title><link>https://www.loldrivers.io/drivers/1ff757df-9a40-4f78-a28a-64830440abf7/</link><guid>https://www.loldrivers.io/drivers/1ff757df-9a40-4f78-a28a-64830440abf7/</guid><pubDate>Sat, 06 May 2023 00:00:00 GMT</pubDate><description></description></item><item><title>bedaisy.sys</title><link>https://www.loldrivers.io/drivers/db666d40-c9fa-4039-bfac-a5d7afd61b67/</link><guid>https://www.loldrivers.io/drivers/db666d40-c9fa-4039-bfac-a5d7afd61b67/</guid><pubDate>Sat, 22 Apr 2023 00:00:00 GMT</pubDate><description>BattlEye Anti-Cheat BEDAISY.SYS PPL privesc.</description></item><item><title>windbg.sys</title><link>https://www.loldrivers.io/drivers/9c3c6e89-3916-498f-81e5-da057ab3ed42/</link><guid>https://www.loldrivers.io/drivers/9c3c6e89-3916-498f-81e5-da057ab3ed42/</guid><pubDate>Sat, 22 Apr 2023 00:00:00 GMT</pubDate><description>Kernel driver seen in a recent CopperStealer campaign.</description></item><item><title>LgCoreTemp.sys</title><link>https://www.loldrivers.io/drivers/2c3884d3-9e4f-4519-b18b-0969612621bc/</link><guid>https://www.loldrivers.io/drivers/2c3884d3-9e4f-4519-b18b-0969612621bc/</guid><pubDate>Sat, 15 Apr 2023 00:00:00 GMT</pubDate><description></description></item><item><title>SSPORT.sys</title><link>https://www.loldrivers.io/drivers/c854b612-0b9f-4fc3-a7b8-a93bed7a291e/</link><guid>https://www.loldrivers.io/drivers/c854b612-0b9f-4fc3-a7b8-a93bed7a291e/</guid><pubDate>Sat, 15 Apr 2023 00:00:00 GMT</pubDate><description></description></item><item><title>dcr.sys</title><link>https://www.loldrivers.io/drivers/b1dd91b1-9ba3-4d68-a2d1-919039e18430/</link><guid>https://www.loldrivers.io/drivers/b1dd91b1-9ba3-4d68-a2d1-919039e18430/</guid><pubDate>Fri, 14 Apr 2023 00:00:00 GMT</pubDate><description>DriveCrypt Dcr.sys vulnerability exploit for bypassing x64 DSE</description></item><item><title>blacklotus_driver.sys</title><link>https://www.loldrivers.io/drivers/8750b245-af35-4bc6-9af3-dc858f9db64f/</link><guid>https://www.loldrivers.io/drivers/8750b245-af35-4bc6-9af3-dc858f9db64f/</guid><pubDate>Wed, 05 Apr 2023 00:00:00 GMT</pubDate><description>The first in-the-wild UEFI bootkit bypassing UEFI Secure Boot on fully updated UEFI systems is now a reality. Once the persistence is configured, the BlackLotus bootkit is executed on every system start. The bootkits goal is to deploy a kernel driver and a final user-mode component.</description></item><item><title>2.sys</title><link>https://www.loldrivers.io/drivers/0c0198a3-5c63-4a9b-abe9-88a810602329/</link><guid>https://www.loldrivers.io/drivers/0c0198a3-5c63-4a9b-abe9-88a810602329/</guid><pubDate>Sat, 04 Mar 2023 00:00:00 GMT</pubDate><description>Driver categorized as POORTRY by Mandiant.</description></item><item><title>4.sys</title><link>https://www.loldrivers.io/drivers/05d7cfea-1fb9-4559-8837-d97b713254fe/</link><guid>https://www.loldrivers.io/drivers/05d7cfea-1fb9-4559-8837-d97b713254fe/</guid><pubDate>Sat, 04 Mar 2023 00:00:00 GMT</pubDate><description>SentinelOne has observed prominent threat actors abusing legitimately signed Microsoft drivers in active intrusions into telecommunication, BPO, MSSP, and financial services businesses.
Investigations into these intrusions led to the discovery of POORTRY and STONESTOP malware, part of a small toolkit designed to terminate AV and EDR processes.
We first reported our discovery to Microsoft’s Security Response Center (MSRC) in October 2022 and received an official case number (75361). Today, MSRC released an associated advisory under ADV220005.
This research is being released alongside Mandiant, a SentinelOne technology and incident response partner.</description></item><item><title>7.sys</title><link>https://www.loldrivers.io/drivers/f7f88ef4-ada4-4210-a40d-9d84142ef0fb/</link><guid>https://www.loldrivers.io/drivers/f7f88ef4-ada4-4210-a40d-9d84142ef0fb/</guid><pubDate>Sat, 04 Mar 2023 00:00:00 GMT</pubDate><description>Driver categorized as POORTRY by Mandiant.</description></item><item><title>gftkyj64.sys</title><link>https://www.loldrivers.io/drivers/0fc0563c-de9f-41d8-806a-748e04d57365/</link><guid>https://www.loldrivers.io/drivers/0fc0563c-de9f-41d8-806a-748e04d57365/</guid><pubDate>Sat, 04 Mar 2023 00:00:00 GMT</pubDate><description>SentinelOne has observed prominent threat actors abusing legitimately signed Microsoft drivers in active intrusions into telecommunication, BPO, MSSP, and financial services businesses.
Investigations into these intrusions led to the discovery of POORTRY and STONESTOP malware, part of a small toolkit designed to terminate AV and EDR processes.
We first reported our discovery to Microsoft’s Security Response Center (MSRC) in October 2022 and received an official case number (75361). Today, MSRC released an associated advisory under ADV220005.
This research is being released alongside Mandiant, a SentinelOne technology and incident response partner.</description></item><item><title>LcTkA.sys</title><link>https://www.loldrivers.io/drivers/d827f7a6-1832-4ddb-90dd-7a8cf1c7f25e/</link><guid>https://www.loldrivers.io/drivers/d827f7a6-1832-4ddb-90dd-7a8cf1c7f25e/</guid><pubDate>Sat, 04 Mar 2023 00:00:00 GMT</pubDate><description>SentinelOne has observed prominent threat actors abusing legitimately signed Microsoft drivers in active intrusions into telecommunication, BPO, MSSP, and financial services businesses.
Investigations into these intrusions led to the discovery of POORTRY and STONESTOP malware, part of a small toolkit designed to terminate AV and EDR processes.
We first reported our discovery to Microsoft’s Security Response Center (MSRC) in October 2022 and received an official case number (75361). Today, MSRC released an associated advisory under ADV220005.
This research is being released alongside Mandiant, a SentinelOne technology and incident response partner.</description></item><item><title>PcieCubed.sys</title><link>https://www.loldrivers.io/drivers/a5ebba11-5a31-48d2-9c6d-78bba397edf1/</link><guid>https://www.loldrivers.io/drivers/a5ebba11-5a31-48d2-9c6d-78bba397edf1/</guid><pubDate>Sat, 04 Mar 2023 00:00:00 GMT</pubDate><description>Driver categorized as POORTRY by Mandiant.</description></item><item><title>POORTRY.sys</title><link>https://www.loldrivers.io/drivers/25d5ebe3-e827-44a4-86fc-898844595c23/</link><guid>https://www.loldrivers.io/drivers/25d5ebe3-e827-44a4-86fc-898844595c23/</guid><pubDate>Sat, 04 Mar 2023 00:00:00 GMT</pubDate><description>Driver categorized as POORTRY by Mandiant.</description></item><item><title>POORTRY1.sys</title><link>https://www.loldrivers.io/drivers/2740a074-1e06-4f75-9c6a-dc57a3f85189/</link><guid>https://www.loldrivers.io/drivers/2740a074-1e06-4f75-9c6a-dc57a3f85189/</guid><pubDate>Sat, 04 Mar 2023 00:00:00 GMT</pubDate><description>Driver categorized as POORTRY by Mandiant.</description></item><item><title>POORTRY2.sys</title><link>https://www.loldrivers.io/drivers/618fbf89-f4e3-4b2a-a4b4-cc4bf7c180e0/</link><guid>https://www.loldrivers.io/drivers/618fbf89-f4e3-4b2a-a4b4-cc4bf7c180e0/</guid><pubDate>Sat, 04 Mar 2023 00:00:00 GMT</pubDate><description>Driver categorized as POORTRY by Mandiant.</description></item><item><title>Sense5Ext.sys</title><link>https://www.loldrivers.io/drivers/70acea34-7ed2-42d5-885c-eca3c2de640c/</link><guid>https://www.loldrivers.io/drivers/70acea34-7ed2-42d5-885c-eca3c2de640c/</guid><pubDate>Sat, 04 Mar 2023 00:00:00 GMT</pubDate><description>Driver categorized as POORTRY by Mandiant.</description></item><item><title>Air_SYSTEM10.sys</title><link>https://www.loldrivers.io/drivers/0eb5f4ce-12a7-4b45-b021-42b995de07c5/</link><guid>https://www.loldrivers.io/drivers/0eb5f4ce-12a7-4b45-b021-42b995de07c5/</guid><pubDate>Fri, 03 Mar 2023 00:00:00 GMT</pubDate><description>Driver categorized as POORTRY by Mandiant.</description></item><item><title>NodeDriver.sys</title><link>https://www.loldrivers.io/drivers/7a5fe570-3b35-4fad-b7d6-7518bd5436a0/</link><guid>https://www.loldrivers.io/drivers/7a5fe570-3b35-4fad-b7d6-7518bd5436a0/</guid><pubDate>Thu, 02 Mar 2023 00:00:00 GMT</pubDate><description>Driver categorized as POORTRY by Mandiant.</description></item><item><title>daxin_blank.sys</title><link>https://www.loldrivers.io/drivers/7e80423f-8b30-4ee2-b904-9f5421826a8c/</link><guid>https://www.loldrivers.io/drivers/7e80423f-8b30-4ee2-b904-9f5421826a8c/</guid><pubDate>Tue, 28 Feb 2023 00:00:00 GMT</pubDate><description>Driver used in the Daxin malware campaign.</description></item><item><title>daxin_blank1.sys</title><link>https://www.loldrivers.io/drivers/1bf3b155-752a-4cc7-beb0-f202e525eb1a/</link><guid>https://www.loldrivers.io/drivers/1bf3b155-752a-4cc7-beb0-f202e525eb1a/</guid><pubDate>Tue, 28 Feb 2023 00:00:00 GMT</pubDate><description>Driver used in the Daxin malware campaign.</description></item><item><title>daxin_blank2.sys</title><link>https://www.loldrivers.io/drivers/2e1531b2-d370-4543-9e2e-5319a1c13c22/</link><guid>https://www.loldrivers.io/drivers/2e1531b2-d370-4543-9e2e-5319a1c13c22/</guid><pubDate>Tue, 28 Feb 2023 00:00:00 GMT</pubDate><description>Driver used in the Daxin malware campaign.</description></item><item><title>daxin_blank3.sys</title><link>https://www.loldrivers.io/drivers/9748d5c8-62dd-474b-a336-0aadb49e5ff9/</link><guid>https://www.loldrivers.io/drivers/9748d5c8-62dd-474b-a336-0aadb49e5ff9/</guid><pubDate>Tue, 28 Feb 2023 00:00:00 GMT</pubDate><description>Driver used in the Daxin malware campaign.</description></item><item><title>daxin_blank4.sys</title><link>https://www.loldrivers.io/drivers/f8bddc8b-49b9-41f7-a877-d15ec3f174f9/</link><guid>https://www.loldrivers.io/drivers/f8bddc8b-49b9-41f7-a877-d15ec3f174f9/</guid><pubDate>Tue, 28 Feb 2023 00:00:00 GMT</pubDate><description>Driver used in the Daxin malware campaign.</description></item><item><title>daxin_blank5.sys</title><link>https://www.loldrivers.io/drivers/0590655c-baa2-481a-b909-463534bd7a5e/</link><guid>https://www.loldrivers.io/drivers/0590655c-baa2-481a-b909-463534bd7a5e/</guid><pubDate>Tue, 28 Feb 2023 00:00:00 GMT</pubDate><description>Driver used in the Daxin malware campaign.</description></item><item><title>daxin_blank6.sys</title><link>https://www.loldrivers.io/drivers/3d1439e9-9a7d-497a-8c6c-74513f825d6a/</link><guid>https://www.loldrivers.io/drivers/3d1439e9-9a7d-497a-8c6c-74513f825d6a/</guid><pubDate>Tue, 28 Feb 2023 00:00:00 GMT</pubDate><description>Driver used in the Daxin malware campaign.</description></item><item><title>ndislan.sys</title><link>https://www.loldrivers.io/drivers/ca1e8664-841f-4e4b-9e67-3f515cc249c6/</link><guid>https://www.loldrivers.io/drivers/ca1e8664-841f-4e4b-9e67-3f515cc249c6/</guid><pubDate>Tue, 28 Feb 2023 00:00:00 GMT</pubDate><description>Driver used in the Daxin malware campaign.</description></item><item><title>ntbios_2.sys</title><link>https://www.loldrivers.io/drivers/33a9c9ae-5ca3-442d-9f0f-2615637c1c57/</link><guid>https://www.loldrivers.io/drivers/33a9c9ae-5ca3-442d-9f0f-2615637c1c57/</guid><pubDate>Tue, 28 Feb 2023 00:00:00 GMT</pubDate><description>Driver used in the Daxin malware campaign.</description></item><item><title>ntbios.sys</title><link>https://www.loldrivers.io/drivers/eef1fcf4-8c54-420b-8d38-9c5f95129dcc/</link><guid>https://www.loldrivers.io/drivers/eef1fcf4-8c54-420b-8d38-9c5f95129dcc/</guid><pubDate>Tue, 28 Feb 2023 00:00:00 GMT</pubDate><description>Driver used in the Daxin malware campaign.</description></item><item><title>wantd_2.sys</title><link>https://www.loldrivers.io/drivers/aa687f89-4f3b-4b59-b64e-fee5e2ae2310/</link><guid>https://www.loldrivers.io/drivers/aa687f89-4f3b-4b59-b64e-fee5e2ae2310/</guid><pubDate>Tue, 28 Feb 2023 00:00:00 GMT</pubDate><description>Driver used in the Daxin malware campaign.</description></item><item><title>wantd_3.sys</title><link>https://www.loldrivers.io/drivers/a22104a8-126d-449f-ba3e-28678c60c587/</link><guid>https://www.loldrivers.io/drivers/a22104a8-126d-449f-ba3e-28678c60c587/</guid><pubDate>Tue, 28 Feb 2023 00:00:00 GMT</pubDate><description>Driver used in the Daxin malware campaign.</description></item><item><title>wantd_4.sys</title><link>https://www.loldrivers.io/drivers/72637cb1-5ca2-4ad0-a5df-20da17b231b5/</link><guid>https://www.loldrivers.io/drivers/72637cb1-5ca2-4ad0-a5df-20da17b231b5/</guid><pubDate>Tue, 28 Feb 2023 00:00:00 GMT</pubDate><description>Driver used in the Daxin malware campaign.</description></item><item><title>wantd_5.sys</title><link>https://www.loldrivers.io/drivers/3277cecc-f4b4-4a00-be01-9da83e013bcd/</link><guid>https://www.loldrivers.io/drivers/3277cecc-f4b4-4a00-be01-9da83e013bcd/</guid><pubDate>Tue, 28 Feb 2023 00:00:00 GMT</pubDate><description>Driver used in the Daxin malware campaign.</description></item><item><title>wantd_6.sys</title><link>https://www.loldrivers.io/drivers/127cde1d-905e-4c67-a2c3-04ea4deaea7d/</link><guid>https://www.loldrivers.io/drivers/127cde1d-905e-4c67-a2c3-04ea4deaea7d/</guid><pubDate>Tue, 28 Feb 2023 00:00:00 GMT</pubDate><description>Driver used in the Daxin malware campaign.</description></item><item><title>wantd.sys</title><link>https://www.loldrivers.io/drivers/892292f9-b87c-40a5-80e5-8c9b02914e8b/</link><guid>https://www.loldrivers.io/drivers/892292f9-b87c-40a5-80e5-8c9b02914e8b/</guid><pubDate>Tue, 28 Feb 2023 00:00:00 GMT</pubDate><description>Driver used in the Daxin malware campaign.</description></item><item><title>1.sys</title><link>https://www.loldrivers.io/drivers/a5792a63-ba77-44ac-bd4a-134b24b01033/</link><guid>https://www.loldrivers.io/drivers/a5792a63-ba77-44ac-bd4a-134b24b01033/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>80.sys</title><link>https://www.loldrivers.io/drivers/2cc3dd4f-8a1e-4f1f-9871-0a14815949b4/</link><guid>https://www.loldrivers.io/drivers/2cc3dd4f-8a1e-4f1f-9871-0a14815949b4/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>81.sys</title><link>https://www.loldrivers.io/drivers/4137ecf0-05e7-463a-94da-47b7259d4433/</link><guid>https://www.loldrivers.io/drivers/4137ecf0-05e7-463a-94da-47b7259d4433/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>ADV64DRV.sys</title><link>https://www.loldrivers.io/drivers/24fb7bab-b8c3-46ea-a370-c84d2f0ff614/</link><guid>https://www.loldrivers.io/drivers/24fb7bab-b8c3-46ea-a370-c84d2f0ff614/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>Agent64.sys</title><link>https://www.loldrivers.io/drivers/5943b267-64f3-40d4-8669-354f23dec122/</link><guid>https://www.loldrivers.io/drivers/5943b267-64f3-40d4-8669-354f23dec122/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>ALSysIO64.sys</title><link>https://www.loldrivers.io/drivers/4d365dd0-34c3-492e-a2bd-c16266796ae5/</link><guid>https://www.loldrivers.io/drivers/4d365dd0-34c3-492e-a2bd-c16266796ae5/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>AMDPowerProfiler.sys</title><link>https://www.loldrivers.io/drivers/9a4fb66e-9084-4b21-9d76-a7afbe330606/</link><guid>https://www.loldrivers.io/drivers/9a4fb66e-9084-4b21-9d76-a7afbe330606/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description>AMD uProf AMDPowerProfiler.sys is affected by CVE-2021-26334. Insufficient access control permits lower-privileged callers to access model-specific registers, which can lead to privilege escalation and ring-0 code execution. AMD addresses the issue in the Windows uProf 3.4.494 release.</description></item><item><title>AMDRyzenMasterDriver.sys</title><link>https://www.loldrivers.io/drivers/13973a71-412f-4a18-a2a6-476d3853f8de/</link><guid>https://www.loldrivers.io/drivers/13973a71-412f-4a18-a2a6-476d3853f8de/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description>AMD Ryzen Master drivers affected by CVE-2023-20564 insufficiently validate IOCTL input buffers. A privileged caller can read or write memory through the exposed interface, potentially enabling arbitrary kernel execution.</description></item><item><title>amifldrv64.sys</title><link>https://www.loldrivers.io/drivers/34fa6ba4-dc7c-4fd6-b947-8a0bb8ebd031/</link><guid>https://www.loldrivers.io/drivers/34fa6ba4-dc7c-4fd6-b947-8a0bb8ebd031/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>amp.sys</title><link>https://www.loldrivers.io/drivers/ca768fc5-9b5c-4ced-90ab-fd6be9a70199/</link><guid>https://www.loldrivers.io/drivers/ca768fc5-9b5c-4ced-90ab-fd6be9a70199/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>asio.sys</title><link>https://www.loldrivers.io/drivers/2651f5c4-d9e1-4b06-92be-e9e7313f87c4/</link><guid>https://www.loldrivers.io/drivers/2651f5c4-d9e1-4b06-92be-e9e7313f87c4/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description>ASUS AsIO hardware-access drivers expose physical-memory mapping and I/O-port operations to user mode. These primitives can be abused to read or modify privileged system state and execute code in kernel context.</description></item><item><title>ASIO32.sys</title><link>https://www.loldrivers.io/drivers/920e3326-e5dc-446a-9993-6ec05266e0e0/</link><guid>https://www.loldrivers.io/drivers/920e3326-e5dc-446a-9993-6ec05266e0e0/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>asmmap64.sys</title><link>https://www.loldrivers.io/drivers/d0048840-970f-4ad5-9a07-1d39469d721f/</link><guid>https://www.loldrivers.io/drivers/d0048840-970f-4ad5-9a07-1d39469d721f/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description>ASUS asmmap64 is a memory-mapping driver that exposes physical-memory mapping to user mode. A privileged caller can abuse the interface to read or modify kernel and physical memory.</description></item><item><title>AsrAutoChkUpdDrv.sys</title><link>https://www.loldrivers.io/drivers/b72f7335-6f27-42c5-85f5-ed7eb9016eac/</link><guid>https://www.loldrivers.io/drivers/b72f7335-6f27-42c5-85f5-ed7eb9016eac/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>AsrDrv10.sys</title><link>https://www.loldrivers.io/drivers/0258df5c-c3c1-4ed5-ba8f-846d91526ffe/</link><guid>https://www.loldrivers.io/drivers/0258df5c-c3c1-4ed5-ba8f-846d91526ffe/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>AsrDrv101.sys</title><link>https://www.loldrivers.io/drivers/51c342f3-0b91-4674-8f81-bc016855f30f/</link><guid>https://www.loldrivers.io/drivers/51c342f3-0b91-4674-8f81-bc016855f30f/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>AsrDrv102.sys</title><link>https://www.loldrivers.io/drivers/5af9abf0-d8de-4e9b-8141-e9e97a31901a/</link><guid>https://www.loldrivers.io/drivers/5af9abf0-d8de-4e9b-8141-e9e97a31901a/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>AsrDrv103.sys</title><link>https://www.loldrivers.io/drivers/32ccd436-eb13-4ab3-83d4-3e5471f4e364/</link><guid>https://www.loldrivers.io/drivers/32ccd436-eb13-4ab3-83d4-3e5471f4e364/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>asrdrv104.sys</title><link>https://www.loldrivers.io/drivers/9889da50-3908-4499-a729-187295a60a0e/</link><guid>https://www.loldrivers.io/drivers/9889da50-3908-4499-a729-187295a60a0e/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>AsrDrv106.sys</title><link>https://www.loldrivers.io/drivers/6a50e368-1120-434b-9232-1a0702c80437/</link><guid>https://www.loldrivers.io/drivers/6a50e368-1120-434b-9232-1a0702c80437/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description>ASRock AsrDrv106 drivers expose physical-memory mapping, contiguous memory allocation, and port-I/O primitives through user-controlled IOCTL handlers, enabling privileged manipulation of kernel memory.</description></item><item><title>AsrIbDrv.sys</title><link>https://www.loldrivers.io/drivers/31797996-6973-402d-a4a0-d01ce51e02c0/</link><guid>https://www.loldrivers.io/drivers/31797996-6973-402d-a4a0-d01ce51e02c0/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>AsrOmgDrv.sys</title><link>https://www.loldrivers.io/drivers/3f39af20-802a-4909-a5de-7f6fe7aab350/</link><guid>https://www.loldrivers.io/drivers/3f39af20-802a-4909-a5de-7f6fe7aab350/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>AsrRapidStartDrv.sys</title><link>https://www.loldrivers.io/drivers/19d16518-4aee-4983-ba89-dbbe0fa8a3e7/</link><guid>https://www.loldrivers.io/drivers/19d16518-4aee-4983-ba89-dbbe0fa8a3e7/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>AsrSetupDrv103.sys</title><link>https://www.loldrivers.io/drivers/19003e00-d42d-4cbe-91f3-756451bdd7da/</link><guid>https://www.loldrivers.io/drivers/19003e00-d42d-4cbe-91f3-756451bdd7da/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>AsrSmartConnectDrv.sys</title><link>https://www.loldrivers.io/drivers/57f63efb-dc43-4dba-9413-173e3e4be750/</link><guid>https://www.loldrivers.io/drivers/57f63efb-dc43-4dba-9413-173e3e4be750/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>aswArPot.sys</title><link>https://www.loldrivers.io/drivers/57fc510a-e649-4599-b83e-8f3605e3d1d9/</link><guid>https://www.loldrivers.io/drivers/57fc510a-e649-4599-b83e-8f3605e3d1d9/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description>Avast and AVG Anti Rootkit driver aswArPot.sys versions before 22.1 are affected by CVE-2022-26522 and CVE-2022-26523. Double-fetch races in kernel handlers allow a non-administrator user to corrupt kernel memory and execute code in kernel context, enabling local privilege escalation and security-product bypass.</description></item><item><title>aswVmm.sys</title><link>https://www.loldrivers.io/drivers/a845a05c-5357-4b78-9783-16b4d34b2cb0/</link><guid>https://www.loldrivers.io/drivers/a845a05c-5357-4b78-9783-16b4d34b2cb0/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>atillk64.sys</title><link>https://www.loldrivers.io/drivers/61514cbd-6f34-4a3e-a022-9ecbccc16feb/</link><guid>https://www.loldrivers.io/drivers/61514cbd-6f34-4a3e-a022-9ecbccc16feb/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>ATSZIO.sys</title><link>https://www.loldrivers.io/drivers/23f11e19-0776-4dd4-9c9c-7f6b60f8553f/</link><guid>https://www.loldrivers.io/drivers/23f11e19-0776-4dd4-9c9c-7f6b60f8553f/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description>ASUS ATSZIO64.sys version 0.2.1.7 is affected by CVE-2024-33222, which permits local privilege escalation and arbitrary code execution through crafted IOCTL requests. The tracked x64 build exposes MSR read and write through IOCTLs 0x88070F88 and 0x88070F8C, maps selected ranges of \Device\PhysicalMemory, and returns physical addresses for contiguous allocations. These unrestricted hardware primitives can be used to modify kernel state.</description></item><item><title>b.sys</title><link>https://www.loldrivers.io/drivers/579a0516-1177-45ce-ad9e-45f53b28dcdc/</link><guid>https://www.loldrivers.io/drivers/579a0516-1177-45ce-ad9e-45f53b28dcdc/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>b1.sys</title><link>https://www.loldrivers.io/drivers/69b924ab-2e4a-4eae-8091-4151c238136e/</link><guid>https://www.loldrivers.io/drivers/69b924ab-2e4a-4eae-8091-4151c238136e/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>b3.sys</title><link>https://www.loldrivers.io/drivers/adfb015a-f453-4b9e-a247-50f146209eb0/</link><guid>https://www.loldrivers.io/drivers/adfb015a-f453-4b9e-a247-50f146209eb0/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>b4.sys</title><link>https://www.loldrivers.io/drivers/d1441172-cc15-4a96-b782-f440bfb681e1/</link><guid>https://www.loldrivers.io/drivers/d1441172-cc15-4a96-b782-f440bfb681e1/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>bandai.sys</title><link>https://www.loldrivers.io/drivers/058fb356-e0ff-4f5e-8293-319feb005db2/</link><guid>https://www.loldrivers.io/drivers/058fb356-e0ff-4f5e-8293-319feb005db2/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>Black.sys</title><link>https://www.loldrivers.io/drivers/4b047bb8-c605-4664-baed-25bb70e864a1/</link><guid>https://www.loldrivers.io/drivers/4b047bb8-c605-4664-baed-25bb70e864a1/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>BlackBoneDrv10.sys</title><link>https://www.loldrivers.io/drivers/722772ee-a461-48ec-933d-f3df1578963e/</link><guid>https://www.loldrivers.io/drivers/722772ee-a461-48ec-933d-f3df1578963e/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>Bs_Def.sys</title><link>https://www.loldrivers.io/drivers/3ac0eda2-a844-4a9d-9cfa-c25a9e05d678/</link><guid>https://www.loldrivers.io/drivers/3ac0eda2-a844-4a9d-9cfa-c25a9e05d678/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>BS_Def64.sys</title><link>https://www.loldrivers.io/drivers/4a80da66-f8f1-4af9-ba56-696cfe6c1e10/</link><guid>https://www.loldrivers.io/drivers/4a80da66-f8f1-4af9-ba56-696cfe6c1e10/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>BS_Flash64.sys</title><link>https://www.loldrivers.io/drivers/e299b0b6-e5e2-45b3-bf0b-c008068cebfa/</link><guid>https://www.loldrivers.io/drivers/e299b0b6-e5e2-45b3-bf0b-c008068cebfa/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>BS_HWMIO64_W10.sys</title><link>https://www.loldrivers.io/drivers/a66d0413-cc82-4f1e-bcf1-0dcf9d79f6c0/</link><guid>https://www.loldrivers.io/drivers/a66d0413-cc82-4f1e-bcf1-0dcf9d79f6c0/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>BS_HWMIo64.sys</title><link>https://www.loldrivers.io/drivers/d158321b-4d56-49c5-9a18-bcff9f4a2ebe/</link><guid>https://www.loldrivers.io/drivers/d158321b-4d56-49c5-9a18-bcff9f4a2ebe/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>BS_I2c64.sys</title><link>https://www.loldrivers.io/drivers/de4dd27a-1f7e-4271-98a4-55395ab6aabf/</link><guid>https://www.loldrivers.io/drivers/de4dd27a-1f7e-4271-98a4-55395ab6aabf/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>BS_RCIO.sys</title><link>https://www.loldrivers.io/drivers/0a2f2700-97b5-42b6-b121-38e5f03e9957/</link><guid>https://www.loldrivers.io/drivers/0a2f2700-97b5-42b6-b121-38e5f03e9957/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>BS_RCIO64.sys</title><link>https://www.loldrivers.io/drivers/e7c958da-fd5d-40d6-975e-582c6fee7f69/</link><guid>https://www.loldrivers.io/drivers/e7c958da-fd5d-40d6-975e-582c6fee7f69/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description>BIOSTAR BS_RCIO64_W10 exposes IOCTLs 0x226004 and 0x226008 that map caller-selected physical addresses with MmMapIoSpace and read from or write to the mapped range. Additional IOCTLs expose raw port and PCI configuration access, providing privileged hardware-control primitives suitable for kernel tampering.</description></item><item><title>BSMEMx64.sys</title><link>https://www.loldrivers.io/drivers/9e87b6b0-00ed-4259-bcd7-05e2c924d58c/</link><guid>https://www.loldrivers.io/drivers/9e87b6b0-00ed-4259-bcd7-05e2c924d58c/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>BSMI.sys</title><link>https://www.loldrivers.io/drivers/bf01915d-045f-442c-a74e-25c56182123f/</link><guid>https://www.loldrivers.io/drivers/bf01915d-045f-442c-a74e-25c56182123f/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>BSMIx64.sys</title><link>https://www.loldrivers.io/drivers/47724cc1-bf75-4ab7-a47a-355a9aa30de1/</link><guid>https://www.loldrivers.io/drivers/47724cc1-bf75-4ab7-a47a-355a9aa30de1/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>bw.sys</title><link>https://www.loldrivers.io/drivers/578d4909-c2ba-4363-b6e3-98fb62d5e55c/</link><guid>https://www.loldrivers.io/drivers/578d4909-c2ba-4363-b6e3-98fb62d5e55c/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>bwrs.sys</title><link>https://www.loldrivers.io/drivers/204eccdf-99ca-4f2a-a325-8ebe34fd29a1/</link><guid>https://www.loldrivers.io/drivers/204eccdf-99ca-4f2a-a325-8ebe34fd29a1/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>bwrsh.sys</title><link>https://www.loldrivers.io/drivers/974de971-1f78-47b9-8049-6c34f294acd5/</link><guid>https://www.loldrivers.io/drivers/974de971-1f78-47b9-8049-6c34f294acd5/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>c.sys</title><link>https://www.loldrivers.io/drivers/404f6db5-6be8-44a9-9898-badd56f96721/</link><guid>https://www.loldrivers.io/drivers/404f6db5-6be8-44a9-9898-badd56f96721/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>capcom.sys</title><link>https://www.loldrivers.io/drivers/b51c441a-12c7-407d-9517-559cc0030cf6/</link><guid>https://www.loldrivers.io/drivers/b51c441a-12c7-407d-9517-559cc0030cf6/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>CITMDRV_AMD64.sys</title><link>https://www.loldrivers.io/drivers/f3215c19-8053-458c-81a5-90a74c5d2e6d/</link><guid>https://www.loldrivers.io/drivers/f3215c19-8053-458c-81a5-90a74c5d2e6d/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>CITMDRV_IA64.sys</title><link>https://www.loldrivers.io/drivers/0f21a584-6ace-4242-82cb-9766cea6973a/</link><guid>https://www.loldrivers.io/drivers/0f21a584-6ace-4242-82cb-9766cea6973a/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>CorsairLLAccess64.sys</title><link>https://www.loldrivers.io/drivers/ff74f03e-e4ce-4242-bfe3-60601056bb34/</link><guid>https://www.loldrivers.io/drivers/ff74f03e-e4ce-4242-bfe3-60601056bb34/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>cpupress.sys</title><link>https://www.loldrivers.io/drivers/c0645f0f-9b97-4fe9-811e-2e45c250c9ef/</link><guid>https://www.loldrivers.io/drivers/c0645f0f-9b97-4fe9-811e-2e45c250c9ef/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>cpuz_x64.sys</title><link>https://www.loldrivers.io/drivers/de003542-80e1-4aa0-9b99-ed8647a93a6e/</link><guid>https://www.loldrivers.io/drivers/de003542-80e1-4aa0-9b99-ed8647a93a6e/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>cpuz.sys</title><link>https://www.loldrivers.io/drivers/0f59ce3b-20ac-41ba-8010-2abc74827eb8/</link><guid>https://www.loldrivers.io/drivers/0f59ce3b-20ac-41ba-8010-2abc74827eb8/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>cpuz141.sys</title><link>https://www.loldrivers.io/drivers/fab98aaa-e4e7-4c4a-af65-c00d35cf66e9/</link><guid>https://www.loldrivers.io/drivers/fab98aaa-e4e7-4c4a-af65-c00d35cf66e9/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>d.sys</title><link>https://www.loldrivers.io/drivers/7a7630d6-d007-4d84-a17d-81236d9693e1/</link><guid>https://www.loldrivers.io/drivers/7a7630d6-d007-4d84-a17d-81236d9693e1/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>d2.sys</title><link>https://www.loldrivers.io/drivers/d05a0a6c-c037-4647-99ac-c41593190223/</link><guid>https://www.loldrivers.io/drivers/d05a0a6c-c037-4647-99ac-c41593190223/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>d3.sys</title><link>https://www.loldrivers.io/drivers/13b2424a-d337-4bc7-ad1d-2049c79906b4/</link><guid>https://www.loldrivers.io/drivers/13b2424a-d337-4bc7-ad1d-2049c79906b4/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>d4.sys</title><link>https://www.loldrivers.io/drivers/c2e70ee6-2f13-4d43-ad5a-c2bf033cc457/</link><guid>https://www.loldrivers.io/drivers/c2e70ee6-2f13-4d43-ad5a-c2bf033cc457/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>dbk64.sys</title><link>https://www.loldrivers.io/drivers/1524a54d-520d-4fa4-a7d5-aaaa066fbfc4/</link><guid>https://www.loldrivers.io/drivers/1524a54d-520d-4fa4-a7d5-aaaa066fbfc4/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>dbutil_2_3.sys</title><link>https://www.loldrivers.io/drivers/a4eabc75-edf6-4b74-9a24-6a26187adabf/</link><guid>https://www.loldrivers.io/drivers/a4eabc75-edf6-4b74-9a24-6a26187adabf/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>dbutil.sys</title><link>https://www.loldrivers.io/drivers/8d14d798-338f-471e-bacb-6d9371c0f529/</link><guid>https://www.loldrivers.io/drivers/8d14d798-338f-471e-bacb-6d9371c0f529/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>DBUtilDrv2.sys</title><link>https://www.loldrivers.io/drivers/bb808089-5857-4df2-8998-753a7106cb44/</link><guid>https://www.loldrivers.io/drivers/bb808089-5857-4df2-8998-753a7106cb44/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description>Dell DBUtilDrv2.sys versions 2.5, 2.6, and 2.7 all contain a write-what-where condition allowing kernel memory read/write. Dell released v2.7 as a remediation for CVE-2021-36276 but the fix was incomplete. Rapid7 confirmed v2.7 retains the kernel memory primitive and published the dellicious PoC and a Metasploit module (post/windows/manage/dell_memory_protect) that works against both v2.5 and v2.7. Dell categorized the v2.7 issue as a weakness rather than a vulnerability, stating it requires admin privileges.</description></item><item><title>Dh_Kernel_10.sys</title><link>https://www.loldrivers.io/drivers/dfce8b0f-d857-4808-80ef-61273c7a4183/</link><guid>https://www.loldrivers.io/drivers/dfce8b0f-d857-4808-80ef-61273c7a4183/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>Dh_Kernel.sys</title><link>https://www.loldrivers.io/drivers/43d0af25-c066-471f-bb73-6ce25dc7e0eb/</link><guid>https://www.loldrivers.io/drivers/43d0af25-c066-471f-bb73-6ce25dc7e0eb/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>DirectIo.sys</title><link>https://www.loldrivers.io/drivers/ce2d41fd-908f-414c-b6b5-338298f425b8/</link><guid>https://www.loldrivers.io/drivers/ce2d41fd-908f-414c-b6b5-338298f425b8/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>driver7-x64.sys</title><link>https://www.loldrivers.io/drivers/48bc2815-85ec-4436-a51a-69810c8cb171/</link><guid>https://www.loldrivers.io/drivers/48bc2815-85ec-4436-a51a-69810c8cb171/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>driver7-x86-withoutdbg.sys</title><link>https://www.loldrivers.io/drivers/d9f2c3d6-160c-4eb3-8547-894fcf810342/</link><guid>https://www.loldrivers.io/drivers/d9f2c3d6-160c-4eb3-8547-894fcf810342/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>driver7-x86.sys</title><link>https://www.loldrivers.io/drivers/670dc258-78b5-4552-a16b-b41917c86f8d/</link><guid>https://www.loldrivers.io/drivers/670dc258-78b5-4552-a16b-b41917c86f8d/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>elbycdio.sys</title><link>https://www.loldrivers.io/drivers/855ade1f-8a9e-4c9d-ab8e-d7e409609852/</link><guid>https://www.loldrivers.io/drivers/855ade1f-8a9e-4c9d-ab8e-d7e409609852/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description>elbycdio.sys is a vulnerable driver. CVE-2009-0824.</description></item><item><title>elrawdsk.sys</title><link>https://www.loldrivers.io/drivers/205721b7-b83b-414a-b4b5-8bacb4a37777/</link><guid>https://www.loldrivers.io/drivers/205721b7-b83b-414a-b4b5-8bacb4a37777/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>EneIo64.sys</title><link>https://www.loldrivers.io/drivers/9b65dba4-81a0-48cc-8ff0-a4f353881062/</link><guid>https://www.loldrivers.io/drivers/9b65dba4-81a0-48cc-8ff0-a4f353881062/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>EneTechIo64.sys</title><link>https://www.loldrivers.io/drivers/d64167b6-f281-41d8-9535-6cb925e77aec/</link><guid>https://www.loldrivers.io/drivers/d64167b6-f281-41d8-9535-6cb925e77aec/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>FairplayKD.sys</title><link>https://www.loldrivers.io/drivers/31686f0e-3748-48c2-be09-fc8f3252e780/</link><guid>https://www.loldrivers.io/drivers/31686f0e-3748-48c2-be09-fc8f3252e780/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>fiddrv.sys</title><link>https://www.loldrivers.io/drivers/75a933b4-82d8-4eb8-8ed5-a0a2178630a3/</link><guid>https://www.loldrivers.io/drivers/75a933b4-82d8-4eb8-8ed5-a0a2178630a3/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>fiddrv64.sys</title><link>https://www.loldrivers.io/drivers/64f3d4b0-6d2b-4275-b3d4-15d092af4092/</link><guid>https://www.loldrivers.io/drivers/64f3d4b0-6d2b-4275-b3d4-15d092af4092/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>fidpcidrv.sys</title><link>https://www.loldrivers.io/drivers/e6338692-90e0-41b1-9481-a47e0df144ad/</link><guid>https://www.loldrivers.io/drivers/e6338692-90e0-41b1-9481-a47e0df144ad/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>fidpcidrv64.sys</title><link>https://www.loldrivers.io/drivers/a005e057-c84f-47cd-9b4b-5b1e51a06ab4/</link><guid>https://www.loldrivers.io/drivers/a005e057-c84f-47cd-9b4b-5b1e51a06ab4/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>full.sys</title><link>https://www.loldrivers.io/drivers/ddbd60c3-0611-4a59-894d-aec84203906f/</link><guid>https://www.loldrivers.io/drivers/ddbd60c3-0611-4a59-894d-aec84203906f/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>gameink.sys</title><link>https://www.loldrivers.io/drivers/86b520f6-cc90-4488-b343-168cad88010d/</link><guid>https://www.loldrivers.io/drivers/86b520f6-cc90-4488-b343-168cad88010d/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>GameTerSafe.sys</title><link>https://www.loldrivers.io/drivers/067589f2-4f29-4dc4-bd50-a2e2ee57b25f/</link><guid>https://www.loldrivers.io/drivers/067589f2-4f29-4dc4-bd50-a2e2ee57b25f/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>gdrv.sys</title><link>https://www.loldrivers.io/drivers/2bea1bca-753c-4f09-bc9f-566ab0193f4a/</link><guid>https://www.loldrivers.io/drivers/2bea1bca-753c-4f09-bc9f-566ab0193f4a/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description>gdrv.sys is vulnerable to multiple CVEs: CVE-2018-19320, CVE-2018-19322, CVE-2018-19323, CVE-2018-19321. Read/Write Physical memory, read/write to/from IO ports, exposes ring0 memcpy-like functionality,  read and write Machine Specific Registers (MSRs). Affected versions: GIGABYTE APP Center v1.05.21 and previous, AORUS GRAPHICS ENGINE v1.33 and previous, XTREME GAMING ENGINE v1.25 and previous, OC GURU II v2.08</description></item><item><title>GLCKIO2.sys</title><link>https://www.loldrivers.io/drivers/868c6920-f6cb-4088-8277-095a1358abe1/</link><guid>https://www.loldrivers.io/drivers/868c6920-f6cb-4088-8277-095a1358abe1/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>goad.sys</title><link>https://www.loldrivers.io/drivers/29cb263b-b0b0-40d5-a97d-5ddf4ba79c1e/</link><guid>https://www.loldrivers.io/drivers/29cb263b-b0b0-40d5-a97d-5ddf4ba79c1e/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>GVCIDrv64.sys</title><link>https://www.loldrivers.io/drivers/7c83cb1a-a5ab-4ea0-aa69-0e9a1d09a82f/</link><guid>https://www.loldrivers.io/drivers/7c83cb1a-a5ab-4ea0-aa69-0e9a1d09a82f/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>HOSTNT.sys</title><link>https://www.loldrivers.io/drivers/e42cd285-4dda-4086-a696-93ab1d6f17ca/</link><guid>https://www.loldrivers.io/drivers/e42cd285-4dda-4086-a696-93ab1d6f17ca/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>HpPortIox64.sys</title><link>https://www.loldrivers.io/drivers/080ff223-f8e0-49c0-a7b5-e97349cf81a0/</link><guid>https://www.loldrivers.io/drivers/080ff223-f8e0-49c0-a7b5-e97349cf81a0/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>hw.sys</title><link>https://www.loldrivers.io/drivers/5969b6dc-b136-480e-a527-3cb2ea2f0da9/</link><guid>https://www.loldrivers.io/drivers/5969b6dc-b136-480e-a527-3cb2ea2f0da9/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>HwOs2Ec10x64.sys</title><link>https://www.loldrivers.io/drivers/3ab0d182-6365-47a7-89f4-34121e889503/</link><guid>https://www.loldrivers.io/drivers/3ab0d182-6365-47a7-89f4-34121e889503/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description>Huawei HwOs2Ec 1.0.0.1 exposes kernel process termination to administrative callers. In the tracked HwOs2Ec.sys build, IOCTL 0x22400C accepts a four-byte PID, rejects only PID 0 and PID 4, opens the target with full process access, and calls ZwTerminateProcess. Proofpoint observed this exact signed driver deployed by Cruciferra as an alternative BYOVD helper for tampering with endpoint security tools.</description></item><item><title>HwOs2Ec7x64.sys</title><link>https://www.loldrivers.io/drivers/e4098d7e-78b3-4da1-96cb-68b27f245e02/</link><guid>https://www.loldrivers.io/drivers/e4098d7e-78b3-4da1-96cb-68b27f245e02/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>HwRwDrv.sys</title><link>https://www.loldrivers.io/drivers/e4609b54-cb25-4433-a75a-7a17f43cec00/</link><guid>https://www.loldrivers.io/drivers/e4609b54-cb25-4433-a75a-7a17f43cec00/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>inpoutx64.sys</title><link>https://www.loldrivers.io/drivers/91ff1575-9ff2-46fd-8bfe-0bb3e3457b7f/</link><guid>https://www.loldrivers.io/drivers/91ff1575-9ff2-46fd-8bfe-0bb3e3457b7f/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>IOMap64.sys</title><link>https://www.loldrivers.io/drivers/f4990bdd-8821-4a3c-a11a-4651e645810c/</link><guid>https://www.loldrivers.io/drivers/f4990bdd-8821-4a3c-a11a-4651e645810c/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>iomem64.sys</title><link>https://www.loldrivers.io/drivers/04d377f9-36e0-42a4-8d47-62232163dc68/</link><guid>https://www.loldrivers.io/drivers/04d377f9-36e0-42a4-8d47-62232163dc68/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>iqvw64e.sys</title><link>https://www.loldrivers.io/drivers/1d2cdef1-de44-4849-80e5-e2fa288df681/</link><guid>https://www.loldrivers.io/drivers/1d2cdef1-de44-4849-80e5-e2fa288df681/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description>(1) IQVW32.sys before 1.3.1.0 and (2) IQVW64.sys before 1.3.1.0 in the Intel Ethernet diagnostics driver for Windows allows local users to cause a denial of service or possibly execute arbitrary code with kernel privileges via a crafted (a) 0x80862013, (b) 0x8086200B, (c) 0x8086200F, or (d) 0x80862007 IOCTL call.</description></item><item><title>kbdcap64.sys</title><link>https://www.loldrivers.io/drivers/6a7d882b-3d9d-4334-be5f-2e29c6bf9ff8/</link><guid>https://www.loldrivers.io/drivers/6a7d882b-3d9d-4334-be5f-2e29c6bf9ff8/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>kEvP64.sys</title><link>https://www.loldrivers.io/drivers/fe2f68e1-e459-4802-9a9a-23bb3c2fd331/</link><guid>https://www.loldrivers.io/drivers/fe2f68e1-e459-4802-9a9a-23bb3c2fd331/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>kprocesshacker.sys</title><link>https://www.loldrivers.io/drivers/edd29861-6984-4dbe-8e7c-22e9b6cf68d0/</link><guid>https://www.loldrivers.io/drivers/edd29861-6984-4dbe-8e7c-22e9b6cf68d0/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>LenovoDiagnosticsDriver.sys</title><link>https://www.loldrivers.io/drivers/81a73e57-2e92-4d21-97d3-1c21eb4c3aea/</link><guid>https://www.loldrivers.io/drivers/81a73e57-2e92-4d21-97d3-1c21eb4c3aea/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description>Lenovo Diagnostics versions before 4.45 are covered by CVE-2022-3699. The vulnerable driver behavior tracked here is limited to confirmed 1.0.2.0 through 1.0.4.0 LenovoDiagnosticsDriver.sys builds. Their low-user device ACL exposes FILE_ANY_ACCESS IOCTLs 0x222010 and 0x222014, which map caller-selected physical addresses and provide unrestricted physical-memory read and write primitives. Later 3.1.0.0 code removed the write path, denied Builtin Users, and limited reads to allowlisted PCI registers, so that build is not tracked here.</description></item><item><title>LgDCatcher.sys</title><link>https://www.loldrivers.io/drivers/a8e999ee-746f-4788-9102-c1d3d2914f56/</link><guid>https://www.loldrivers.io/drivers/a8e999ee-746f-4788-9102-c1d3d2914f56/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>LHA.sys</title><link>https://www.loldrivers.io/drivers/1c7631f0-f92f-4be5-8ba7-3eefb0601d45/</link><guid>https://www.loldrivers.io/drivers/1c7631f0-f92f-4be5-8ba7-3eefb0601d45/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>libnicm.sys</title><link>https://www.loldrivers.io/drivers/2b949a0d-939f-456a-a34f-4589d7712227/</link><guid>https://www.loldrivers.io/drivers/2b949a0d-939f-456a-a34f-4589d7712227/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>Lurker.sys</title><link>https://www.loldrivers.io/drivers/3fb743b8-d3ed-4873-9c95-e212720dde21/</link><guid>https://www.loldrivers.io/drivers/3fb743b8-d3ed-4873-9c95-e212720dde21/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>Lv561av.sys</title><link>https://www.loldrivers.io/drivers/47a351ee-8abe-40d8-bc2b-557390fa0945/</link><guid>https://www.loldrivers.io/drivers/47a351ee-8abe-40d8-bc2b-557390fa0945/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>magdrvamd64.sys</title><link>https://www.loldrivers.io/drivers/cfd36b2e-cf96-498e-aeb6-ee20e7b33bbb/</link><guid>https://www.loldrivers.io/drivers/cfd36b2e-cf96-498e-aeb6-ee20e7b33bbb/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>Mhyprot2.sys</title><link>https://www.loldrivers.io/drivers/57354c82-ff9c-4a54-8377-d195e4ff0a26/</link><guid>https://www.loldrivers.io/drivers/57354c82-ff9c-4a54-8377-d195e4ff0a26/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>mhyprot3.sys</title><link>https://www.loldrivers.io/drivers/2aa003cd-5f36-46a6-ae3d-f5afc2c8baa3/</link><guid>https://www.loldrivers.io/drivers/2aa003cd-5f36-46a6-ae3d-f5afc2c8baa3/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>Monitor_win10_x64.sys</title><link>https://www.loldrivers.io/drivers/ca415ed5-b611-4840-bfb2-6e1eacac33d1/</link><guid>https://www.loldrivers.io/drivers/ca415ed5-b611-4840-bfb2-6e1eacac33d1/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description>CVE-2018-16712</description></item><item><title>MsIo32.sys</title><link>https://www.loldrivers.io/drivers/4e5064b4-48d3-418c-a7a8-f0dc7ac0a176/</link><guid>https://www.loldrivers.io/drivers/4e5064b4-48d3-418c-a7a8-f0dc7ac0a176/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description>The MsIo64.sys and MsIo32.sys drivers in Patriot Viper RGB before 1.1 allow local users (including low integrity processes) to read and write to arbitrary memory locations, and consequently gain NT AUTHORITY\SYSTEM privileges, by mapping \Device\PhysicalMemory into the calling process via ZwOpenSection and ZwMapViewOfSection.</description></item><item><title>MsIo64.sys</title><link>https://www.loldrivers.io/drivers/6d21df78-d718-44df-b722-99eec654f5b2/</link><guid>https://www.loldrivers.io/drivers/6d21df78-d718-44df-b722-99eec654f5b2/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description>The MSI AmbientLink MsIo64 driver 1.0.0.8 has a Buffer Overflow (0x80102040, 0x80102044, 0x80102050,and 0x80102054)</description></item><item><title>msrhook.sys</title><link>https://www.loldrivers.io/drivers/1a1cf88a-96d0-46cd-a24d-1535e4a5f6e3/</link><guid>https://www.loldrivers.io/drivers/1a1cf88a-96d0-46cd-a24d-1535e4a5f6e3/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>mtcBSv64.sys</title><link>https://www.loldrivers.io/drivers/3bc629e8-7bf8-40c2-965b-87eb155e0065/</link><guid>https://www.loldrivers.io/drivers/3bc629e8-7bf8-40c2-965b-87eb155e0065/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>My.sys</title><link>https://www.loldrivers.io/drivers/b7ec29c6-e151-4a9f-a293-e61f04ee6489/</link><guid>https://www.loldrivers.io/drivers/b7ec29c6-e151-4a9f-a293-e61f04ee6489/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>mydrivers.sys</title><link>https://www.loldrivers.io/drivers/d9e00cc7-a8f4-4390-a6dc-0f5423e97da4/</link><guid>https://www.loldrivers.io/drivers/d9e00cc7-a8f4-4390-a6dc-0f5423e97da4/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description>DriverGenius mydrivers.sys 9.2.707.1214 is affected by CVE-2023-1676. IOCTL 0x9C402088 dispatches caller-controlled values to the privileged WRMSR instruction without adequate access control. A local user can corrupt kernel state, execute code in ring 0, and elevate privileges.</description></item><item><title>NBIOLib_X64.sys</title><link>https://www.loldrivers.io/drivers/6fc3034f-8b40-44ef-807a-f61d3ea2dece/</link><guid>https://www.loldrivers.io/drivers/6fc3034f-8b40-44ef-807a-f61d3ea2dece/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>NCHGBIOS2x64.SYS</title><link>https://www.loldrivers.io/drivers/d2806397-9ceb-47c8-b5f3-3aabec182ff5/</link><guid>https://www.loldrivers.io/drivers/d2806397-9ceb-47c8-b5f3-3aabec182ff5/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>ncpl.sys</title><link>https://www.loldrivers.io/drivers/8ff4ab50-05b7-4bfa-b994-1920c4ed4978/</link><guid>https://www.loldrivers.io/drivers/8ff4ab50-05b7-4bfa-b994-1920c4ed4978/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description>ncpl.sys is a vulnerable driver. CVE-2013-3956.</description></item><item><title>netfilterdrv.sys</title><link>https://www.loldrivers.io/drivers/f1dcb0e4-aa53-4e62-ab09-fb7b4a356916/</link><guid>https://www.loldrivers.io/drivers/f1dcb0e4-aa53-4e62-ab09-fb7b4a356916/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>NetFlt.sys</title><link>https://www.loldrivers.io/drivers/30d6c39c-1d93-4101-8dd3-322ff0ab7fb3/</link><guid>https://www.loldrivers.io/drivers/30d6c39c-1d93-4101-8dd3-322ff0ab7fb3/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>NetProxyDriver.sys</title><link>https://www.loldrivers.io/drivers/c1ece07b-e92a-4050-95ee-90e03aa82120/</link><guid>https://www.loldrivers.io/drivers/c1ece07b-e92a-4050-95ee-90e03aa82120/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>ni.sys</title><link>https://www.loldrivers.io/drivers/4f93e19c-4600-4e2e-943f-a986875fd7d2/</link><guid>https://www.loldrivers.io/drivers/4f93e19c-4600-4e2e-943f-a986875fd7d2/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>nicm.sys</title><link>https://www.loldrivers.io/drivers/86cff0de-2536-4b8d-a846-a7312c569597/</link><guid>https://www.loldrivers.io/drivers/86cff0de-2536-4b8d-a846-a7312c569597/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description>nicm.sys is a vulnerable driver. CVE-2013-3956.</description></item><item><title>nscm.sys</title><link>https://www.loldrivers.io/drivers/351ff5ca-f07b-4eb6-9300-d5d31514defb/</link><guid>https://www.loldrivers.io/drivers/351ff5ca-f07b-4eb6-9300-d5d31514defb/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description>nscm.sys is a vulnerable driver. CVE-2013-3956.</description></item><item><title>nstr.sys</title><link>https://www.loldrivers.io/drivers/90e8600a-9b5c-4153-bb06-1d8fbe0ef232/</link><guid>https://www.loldrivers.io/drivers/90e8600a-9b5c-4153-bb06-1d8fbe0ef232/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>nstrwsk.sys</title><link>https://www.loldrivers.io/drivers/e9b099f6-8a12-46f0-a540-40e88cf0ce17/</link><guid>https://www.loldrivers.io/drivers/e9b099f6-8a12-46f0-a540-40e88cf0ce17/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>nt2.sys</title><link>https://www.loldrivers.io/drivers/cacc48e6-6ed8-431c-abee-88ee6c2dc3c1/</link><guid>https://www.loldrivers.io/drivers/cacc48e6-6ed8-431c-abee-88ee6c2dc3c1/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>nt3.sys</title><link>https://www.loldrivers.io/drivers/d5118882-6cdd-4b06-8bf4-e9818f16137e/</link><guid>https://www.loldrivers.io/drivers/d5118882-6cdd-4b06-8bf4-e9818f16137e/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>nt4.sys</title><link>https://www.loldrivers.io/drivers/1d4f7a3a-786b-4a74-b34f-14d44343de9e/</link><guid>https://www.loldrivers.io/drivers/1d4f7a3a-786b-4a74-b34f-14d44343de9e/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>nt5.sys</title><link>https://www.loldrivers.io/drivers/193df066-c27c-4343-a4eb-ad2ac417a4cc/</link><guid>https://www.loldrivers.io/drivers/193df066-c27c-4343-a4eb-ad2ac417a4cc/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>nt6.sys</title><link>https://www.loldrivers.io/drivers/e71f0866-e317-44d4-a456-d6f0c555aa73/</link><guid>https://www.loldrivers.io/drivers/e71f0866-e317-44d4-a456-d6f0c555aa73/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>NTIOLib_X64.sys</title><link>https://www.loldrivers.io/drivers/54d67d79-0268-4c5f-be7e-0f74cd20828a/</link><guid>https://www.loldrivers.io/drivers/54d67d79-0268-4c5f-be7e-0f74cd20828a/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>NTIOLib.sys</title><link>https://www.loldrivers.io/drivers/a7bba474-815f-49be-bddc-4d76a64c866c/</link><guid>https://www.loldrivers.io/drivers/a7bba474-815f-49be-bddc-4d76a64c866c/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>nvflash.sys</title><link>https://www.loldrivers.io/drivers/d55a5955-6220-4f38-ba7d-91339330fe98/</link><guid>https://www.loldrivers.io/drivers/d55a5955-6220-4f38-ba7d-91339330fe98/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>nvflsh64.sys</title><link>https://www.loldrivers.io/drivers/d4664202-d1b9-44d4-97cc-fee2150082db/</link><guid>https://www.loldrivers.io/drivers/d4664202-d1b9-44d4-97cc-fee2150082db/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>OpenLibSys.sys</title><link>https://www.loldrivers.io/drivers/2e4fedb0-30ed-400d-b4e1-b2b2004c1607/</link><guid>https://www.loldrivers.io/drivers/2e4fedb0-30ed-400d-b4e1-b2b2004c1607/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>otipcibus.sys</title><link>https://www.loldrivers.io/drivers/17cf4fac-88f1-467d-9f62-481d33accc5b/</link><guid>https://www.loldrivers.io/drivers/17cf4fac-88f1-467d-9f62-481d33accc5b/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>PanIO.sys</title><link>https://www.loldrivers.io/drivers/5f70bde4-9f81-44a8-9d3e-c6c7cf65bfae/</link><guid>https://www.loldrivers.io/drivers/5f70bde4-9f81-44a8-9d3e-c6c7cf65bfae/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>PanIOx64.sys</title><link>https://www.loldrivers.io/drivers/93c84c08-4683-493d-abf7-22dc2d1cb567/</link><guid>https://www.loldrivers.io/drivers/93c84c08-4683-493d-abf7-22dc2d1cb567/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>PanMonFlt.sys</title><link>https://www.loldrivers.io/drivers/cfdc5cb4-be5c-4dcc-a883-825fa72115b4/</link><guid>https://www.loldrivers.io/drivers/cfdc5cb4-be5c-4dcc-a883-825fa72115b4/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>PanMonFltX64.sys</title><link>https://www.loldrivers.io/drivers/40bfb01b-d251-4c2c-952e-052a89a76f5b/</link><guid>https://www.loldrivers.io/drivers/40bfb01b-d251-4c2c-952e-052a89a76f5b/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>PCHunter.sys</title><link>https://www.loldrivers.io/drivers/a261cd64-0d04-4bf5-ad73-f3bb96bf83cf/</link><guid>https://www.loldrivers.io/drivers/a261cd64-0d04-4bf5-ad73-f3bb96bf83cf/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>PhlashNT.sys</title><link>https://www.loldrivers.io/drivers/be3e49ea-095e-4fdb-9529-f4c2dbb9a9fc/</link><guid>https://www.loldrivers.io/drivers/be3e49ea-095e-4fdb-9529-f4c2dbb9a9fc/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>phymem64.sys</title><link>https://www.loldrivers.io/drivers/47fe1aaf-02cd-4a41-8bf5-0047015a2a6e/</link><guid>https://www.loldrivers.io/drivers/47fe1aaf-02cd-4a41-8bf5-0047015a2a6e/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description>Supermicro phymem drivers expose direct physical-memory operations to user mode. In the tracked 2.3.0.0 build, IOCTL 0x80002000 accepts a physical address and length, maps the range with MmMapIoSpace, builds an MDL, and maps the pages to user mode with MmMapLockedPagesSpecifyCache; 0x80002004 releases the mapping. Adjacent paths provide direct physical-memory reads and port I/O. An administrator with device access can use these primitives to inspect or modify kernel state.</description></item><item><title>Phymemx64.sys</title><link>https://www.loldrivers.io/drivers/268e87ba-ad44-4f3c-986f-26712cac68da/</link><guid>https://www.loldrivers.io/drivers/268e87ba-ad44-4f3c-986f-26712cac68da/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>physmem.sys</title><link>https://www.loldrivers.io/drivers/f4c22f4d-eff8-40c5-8b31-146abe5f17b7/</link><guid>https://www.loldrivers.io/drivers/f4c22f4d-eff8-40c5-8b31-146abe5f17b7/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>piddrv.sys</title><link>https://www.loldrivers.io/drivers/354a9fcf-acf1-4151-94d2-af88116f605c/</link><guid>https://www.loldrivers.io/drivers/354a9fcf-acf1-4151-94d2-af88116f605c/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>piddrv64.sys</title><link>https://www.loldrivers.io/drivers/aaa92ef1-5728-4e15-9fca-b054b02f0fb0/</link><guid>https://www.loldrivers.io/drivers/aaa92ef1-5728-4e15-9fca-b054b02f0fb0/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>ProtectS.sys</title><link>https://www.loldrivers.io/drivers/99668140-a8f6-48f8-86d1-cf3bf693600c/</link><guid>https://www.loldrivers.io/drivers/99668140-a8f6-48f8-86d1-cf3bf693600c/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>Proxy32.sys</title><link>https://www.loldrivers.io/drivers/0d0d204b-f6ce-4ce4-8d76-1724a1676c3f/</link><guid>https://www.loldrivers.io/drivers/0d0d204b-f6ce-4ce4-8d76-1724a1676c3f/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>Proxy64.sys</title><link>https://www.loldrivers.io/drivers/5d3f0b7d-7413-48e6-8d9c-7fc0bb5a66ee/</link><guid>https://www.loldrivers.io/drivers/5d3f0b7d-7413-48e6-8d9c-7fc0bb5a66ee/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>RTCore64.sys</title><link>https://www.loldrivers.io/drivers/e32bc3da-4db1-4858-a62c-6fbe4db6afbd/</link><guid>https://www.loldrivers.io/drivers/e32bc3da-4db1-4858-a62c-6fbe4db6afbd/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description>The driver in Micro-Star MSI Afterburner 4.6.2.15658 (aka RTCore64.sys and RTCore32.sys) allows any authenticated user to read and write to arbitrary memory, I/O ports, and MSRs. This can be exploited for privilege escalation, code execution under high privileges, and information disclosure. These signed drivers can also be used to bypass the Microsoft driver-signing policy to deploy malicious code.</description></item><item><title>rtkio.sys</title><link>https://www.loldrivers.io/drivers/8d3f27bd-c3fd-48d0-913a-e2caa6fbd025/</link><guid>https://www.loldrivers.io/drivers/8d3f27bd-c3fd-48d0-913a-e2caa6fbd025/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>rwdrv.sys</title><link>https://www.loldrivers.io/drivers/fbdd993b-47b1-4448-8c41-24c310802398/</link><guid>https://www.loldrivers.io/drivers/fbdd993b-47b1-4448-8c41-24c310802398/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description>This utility access almost all the computer hardware, including PCI (PCI Express), PCI Index/Data, Memory, Memory Index/Data, I/O Space, I/O Index/Data, Super I/O, Clock Generator, DIMM SPD, SMBus Device, CPU MSR Registers, ATA/ATAPI Identify Data, Disk Read Write, ACPI Tables Dump (include AML decode), Embedded Controller, USB Information, SMBIOS Structures, PCI Option ROMs, MP Configuration Table, E820, EDID and Remote Access. And also a Command Window is provided to access hardware manually.</description></item><item><title>rzpnk.sys</title><link>https://www.loldrivers.io/drivers/1c6e1d3b-f825-4065-9e0c-83386883e40f/</link><guid>https://www.loldrivers.io/drivers/1c6e1d3b-f825-4065-9e0c-83386883e40f/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description>A vulnerability exists in the latest version of Razer Synapse (v2.20.15.1104 as of the day of disclosure) which can be leveraged locally by a malicious application to elevate its privileges to those of NT_AUTHORITY\SYSTEM. The vulnerability lies in a specific IOCTL handler in the rzpnk.sys driver that passes a PID specified by the user to ZwOpenProcess. CVE-2017-9769.</description></item><item><title>sandra.sys</title><link>https://www.loldrivers.io/drivers/bc5e020a-ecff-43c8-b57b-ee17b5f65b21/</link><guid>https://www.loldrivers.io/drivers/bc5e020a-ecff-43c8-b57b-ee17b5f65b21/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>Se64a.sys</title><link>https://www.loldrivers.io/drivers/d819bee2-3bff-481f-a301-acc3d1f5fe58/</link><guid>https://www.loldrivers.io/drivers/d819bee2-3bff-481f-a301-acc3d1f5fe58/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>segwindrvx64.sys</title><link>https://www.loldrivers.io/drivers/a4aa80bc-4ecd-49ab-bc0f-0f49b07fdd7f/</link><guid>https://www.loldrivers.io/drivers/a4aa80bc-4ecd-49ab-bc0f-0f49b07fdd7f/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>semav6msr.sys</title><link>https://www.loldrivers.io/drivers/142453a2-a24d-4b35-8922-6d5939f1c0fc/</link><guid>https://www.loldrivers.io/drivers/142453a2-a24d-4b35-8922-6d5939f1c0fc/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>smep_capcom.sys</title><link>https://www.loldrivers.io/drivers/19897aed-9be8-4111-a7d8-35618b9d75b3/</link><guid>https://www.loldrivers.io/drivers/19897aed-9be8-4111-a7d8-35618b9d75b3/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>smep_namco.sys</title><link>https://www.loldrivers.io/drivers/cce291c8-4534-4362-af45-5f45cd32bd92/</link><guid>https://www.loldrivers.io/drivers/cce291c8-4534-4362-af45-5f45cd32bd92/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>speedfan.sys</title><link>https://www.loldrivers.io/drivers/137daca4-0d7b-48aa-8574-f7eb6ad02526/</link><guid>https://www.loldrivers.io/drivers/137daca4-0d7b-48aa-8574-f7eb6ad02526/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description>speedfan.sys is a vulnerable driver. CVE-2007-5633.</description></item><item><title>superbmc.sys</title><link>https://www.loldrivers.io/drivers/9074a02a-b1ca-4bfb-8918-5b88e91c04a2/</link><guid>https://www.loldrivers.io/drivers/9074a02a-b1ca-4bfb-8918-5b88e91c04a2/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>SysInfo.sys</title><link>https://www.loldrivers.io/drivers/84ccb68d-ce34-4aa2-98d5-7f473c2e1b07/</link><guid>https://www.loldrivers.io/drivers/84ccb68d-ce34-4aa2-98d5-7f473c2e1b07/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>t.sys</title><link>https://www.loldrivers.io/drivers/65660363-0080-4432-abd9-64368dac0283/</link><guid>https://www.loldrivers.io/drivers/65660363-0080-4432-abd9-64368dac0283/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>t3.sys</title><link>https://www.loldrivers.io/drivers/31a962ce-43ef-410f-873a-7ccc8f00332b/</link><guid>https://www.loldrivers.io/drivers/31a962ce-43ef-410f-873a-7ccc8f00332b/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>t7.sys</title><link>https://www.loldrivers.io/drivers/7196366e-04f0-4aaf-9184-ed0a0d21a75f/</link><guid>https://www.loldrivers.io/drivers/7196366e-04f0-4aaf-9184-ed0a0d21a75f/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>t8.sys</title><link>https://www.loldrivers.io/drivers/8c2fa9d1-b2b1-4ba1-bad9-60c44c2c20eb/</link><guid>https://www.loldrivers.io/drivers/8c2fa9d1-b2b1-4ba1-bad9-60c44c2c20eb/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>TestBone.sys</title><link>https://www.loldrivers.io/drivers/be4843ef-a2a8-4a0d-91c6-42e165800bb0/</link><guid>https://www.loldrivers.io/drivers/be4843ef-a2a8-4a0d-91c6-42e165800bb0/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>TGSafe.sys</title><link>https://www.loldrivers.io/drivers/ad693146-4adf-4407-bb20-f2505e34c226/</link><guid>https://www.loldrivers.io/drivers/ad693146-4adf-4407-bb20-f2505e34c226/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>TmComm.sys</title><link>https://www.loldrivers.io/drivers/22aa985b-5fdb-4e38-9382-a496220c27ec/</link><guid>https://www.loldrivers.io/drivers/22aa985b-5fdb-4e38-9382-a496220c27ec/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>UCOREW64.SYS</title><link>https://www.loldrivers.io/drivers/a338a9fc-9fe3-400c-9fe4-69bb7892602d/</link><guid>https://www.loldrivers.io/drivers/a338a9fc-9fe3-400c-9fe4-69bb7892602d/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>vboxdrv.sys</title><link>https://www.loldrivers.io/drivers/2da3a276-9e38-4ee6-903d-d15f7c355e7c/</link><guid>https://www.loldrivers.io/drivers/2da3a276-9e38-4ee6-903d-d15f7c355e7c/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description>Used by unknown actor in Acid Rain malware. vboxdrv.sys is a vulnerable driver.</description></item><item><title>viraglt64.sys</title><link>https://www.loldrivers.io/drivers/c3cca618-5a7f-4a51-8785-cb328fbfb0df/</link><guid>https://www.loldrivers.io/drivers/c3cca618-5a7f-4a51-8785-cb328fbfb0df/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>viragt.sys</title><link>https://www.loldrivers.io/drivers/39742f99-2180-46d7-8538-56667c935cc3/</link><guid>https://www.loldrivers.io/drivers/39742f99-2180-46d7-8538-56667c935cc3/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>vmdrv.sys</title><link>https://www.loldrivers.io/drivers/fdf4f85b-47f4-4c98-a0d5-a6583463f565/</link><guid>https://www.loldrivers.io/drivers/fdf4f85b-47f4-4c98-a0d5-a6583463f565/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>VProEventMonitor.sys</title><link>https://www.loldrivers.io/drivers/4db827b1-325b-444d-9f23-171285a4d12f/</link><guid>https://www.loldrivers.io/drivers/4db827b1-325b-444d-9f23-171285a4d12f/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>WCPU.sys</title><link>https://www.loldrivers.io/drivers/7f645b95-4374-47ae-be1a-e4415308b550/</link><guid>https://www.loldrivers.io/drivers/7f645b95-4374-47ae-be1a-e4415308b550/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>windows-xp-64.sys</title><link>https://www.loldrivers.io/drivers/a1d35b93-e97f-4ddd-a465-2405e804e754/</link><guid>https://www.loldrivers.io/drivers/a1d35b93-e97f-4ddd-a465-2405e804e754/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>windows7-32.sys</title><link>https://www.loldrivers.io/drivers/b45a3fdf-592a-4cd9-81e2-8fe03d554cad/</link><guid>https://www.loldrivers.io/drivers/b45a3fdf-592a-4cd9-81e2-8fe03d554cad/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>windows8-10-32.sys</title><link>https://www.loldrivers.io/drivers/7437388f-821e-421f-a3c1-62ce2c725a6a/</link><guid>https://www.loldrivers.io/drivers/7437388f-821e-421f-a3c1-62ce2c725a6a/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>WinFlash64.sys</title><link>https://www.loldrivers.io/drivers/902249eb-87cb-4c01-8da7-17675d743cd7/</link><guid>https://www.loldrivers.io/drivers/902249eb-87cb-4c01-8da7-17675d743cd7/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>WinIO32.sys</title><link>https://www.loldrivers.io/drivers/0f6c3a28-4d04-474b-a098-37383f984686/</link><guid>https://www.loldrivers.io/drivers/0f6c3a28-4d04-474b-a098-37383f984686/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>WinIO32A.sys</title><link>https://www.loldrivers.io/drivers/1068f5cc-65dd-4fd0-b3d8-1d982b37405f/</link><guid>https://www.loldrivers.io/drivers/1068f5cc-65dd-4fd0-b3d8-1d982b37405f/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>WinIO32B.sys</title><link>https://www.loldrivers.io/drivers/45f2c348-bf17-40ab-8306-ef14231cc996/</link><guid>https://www.loldrivers.io/drivers/45f2c348-bf17-40ab-8306-ef14231cc996/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>winio64.sys</title><link>https://www.loldrivers.io/drivers/94eb0694-29ba-4f8e-b763-86c6371db6cc/</link><guid>https://www.loldrivers.io/drivers/94eb0694-29ba-4f8e-b763-86c6371db6cc/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>WinIo64A.sys</title><link>https://www.loldrivers.io/drivers/2cfede23-67f4-4af7-830f-c95ba30a43ae/</link><guid>https://www.loldrivers.io/drivers/2cfede23-67f4-4af7-830f-c95ba30a43ae/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>WinIo64B.sys</title><link>https://www.loldrivers.io/drivers/457f8b21-202a-4a3d-a18d-b4aaded9ef02/</link><guid>https://www.loldrivers.io/drivers/457f8b21-202a-4a3d-a18d-b4aaded9ef02/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>WinIo64C.sys</title><link>https://www.loldrivers.io/drivers/1ed9d02f-17cf-43dd-9645-a54452468a5e/</link><guid>https://www.loldrivers.io/drivers/1ed9d02f-17cf-43dd-9645-a54452468a5e/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>WINIODrv.sys</title><link>https://www.loldrivers.io/drivers/b745b5da-9cd6-4b3a-badf-fbe487497705/</link><guid>https://www.loldrivers.io/drivers/b745b5da-9cd6-4b3a-badf-fbe487497705/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>WinRing0.sys</title><link>https://www.loldrivers.io/drivers/7bb5ff05-25f8-410d-ae99-c8e8f082d24f/</link><guid>https://www.loldrivers.io/drivers/7bb5ff05-25f8-410d-ae99-c8e8f082d24f/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description>OpenLibSys WinRing0 hardware-access drivers expose MSR, I/O-port, and physical-memory operations to user mode. Attackers can abuse these primitives for kernel-memory access and security-control tampering.</description></item><item><title>WiseUnlo.sys</title><link>https://www.loldrivers.io/drivers/b28cc2ee-d4a2-4fe4-9acb-a7a61cad20c6/</link><guid>https://www.loldrivers.io/drivers/b28cc2ee-d4a2-4fe4-9acb-a7a61cad20c6/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>WYProxy64.sys</title><link>https://www.loldrivers.io/drivers/f93e88c2-d0e8-4347-869f-efa568955e9d/</link><guid>https://www.loldrivers.io/drivers/f93e88c2-d0e8-4347-869f-efa568955e9d/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item><item><title>zam64.sys</title><link>https://www.loldrivers.io/drivers/e5f12b82-8d07-474e-9587-8c7b3714d60c/</link><guid>https://www.loldrivers.io/drivers/e5f12b82-8d07-474e-9587-8c7b3714d60c/</guid><pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate><description></description></item></channel></rss>