Menu

  • Alerts
  • Incidents
  • News
  • Cyber Briefing
  • Cyber Decoded
  • Cyber Hygiene
  • Cyber Review
  • Cyber Tips
  • Definitions
  • Malware
  • Tutorials

Useful Tools

  • Password Generator
No Result
View All Result
Sunday, December 3, 2023
CyberMaterial
  • Education
    • Cyber Decoded
    • Definitions
  • Information
    • Alerts
    • Incidents
    • News
    • Cyber Briefing
  • Insights
    • Cyber Hygiene
    • Cyber Review
    • Tips
    • Tutorials
  • Support
    • Contact Us
Get Help
CyberMaterial
  • Education
    • Cyber Decoded
    • Definitions
  • Information
    • Alerts
    • Incidents
    • News
    • Cyber Briefing
  • Insights
    • Cyber Hygiene
    • Cyber Review
    • Tips
    • Tutorials
  • Support
    • Contact Us
Get Help
No Result
View All Result
CyberMaterial
No Result
View All Result
Home Alerts

34 Windows Drivers Vulnerable to Attacks

November 3, 2023
Reading Time: 8 mins read
in Alerts

In a concerning discovery, researchers have identified a total of 34 unique Windows Driver Model (WDM) and Windows Driver Frameworks (WDF) drivers that could be exploited by non-privileged threat actors to gain full control of devices and execute arbitrary code on the underlying systems.

According to Takahiro Haruyama, a senior threat researcher at VMware Carbon Black, these driver vulnerabilities could allow attackers to erase or alter firmware and even elevate operating system privileges. This research builds on previous studies that used symbolic execution to automate the discovery of vulnerable drivers, focusing specifically on those with firmware access through port I/O and memory-mapped I/O.

Among the identified vulnerable drivers are AODDriver.sys, ComputerZ.sys, dellbios.sys, GEDevDrv.sys, GtcKmdfBs.sys, IoAccess.sys, kerneld.amd64, ngiodriver.sys, nvoclock.sys, PDFWKRNL.sys (CVE-2023-20598), RadHwMgr.sys, rtif.sys, rtport.sys, stdcdrv64.sys, and TdkLib64.sys (CVE-2023-35841). Of these drivers, six allow access to kernel memory, which could be exploited to elevate privilege and bypass security mechanisms like kernel address space layout randomization (KASLR). Furthermore, seven of the drivers, including Intel’s stdcdrv64.sys, could be utilized to erase firmware in the SPI flash memory, potentially rendering the system unbootable. Intel has issued a fix for this specific problem.

VMware also pointed out that while certain WDF drivers, like WDTKernel.sys and H2OFFT64.sys, are not vulnerable in terms of access control, they could be easily weaponized by privileged threat actors for a “Bring Your Own Vulnerable Driver” (BYOVD) attack. This technique has been used by various adversaries, including the North Korea-linked Lazarus Group, to gain elevated privileges and disable security software on compromised endpoints to evade detection.

Haruyama noted that while the current scope of the APIs and instructions targeted by the IDAPython script for automating static code analysis of x64 vulnerable drivers is narrow and limited to firmware access, it could be extended to cover other attack vectors, such as terminating arbitrary processes.

References:
  • Hunting Vulnerable Kernel Drivers
  • VMW Carbon Black TAU discovered 34 unique vulnerable WDF/WDM drivers (237 file hashes), including ones made by major chip/BIOS/PC makers.
Tags: AttackersCyber AlertCyber Alerts 2023CybersecurityNovember 2023Threat ActorsVmwareVulnerabilitiesWindows
ADVERTISEMENT

Related Posts

December 01, 2023 – Cyber Briefing

December 01, 2023 – Cyber Briefing

December 1, 2023
US Sanctions North Korean Hackers

US Sanctions North Korean Hackers

December 1, 2023
Meta Counters Foreign Influence

Meta Counters Foreign Influence

December 1, 2023
Lazarus Group’s $3B Crypto Gains

Lazarus Group’s $3B Crypto Gains

December 1, 2023
UK SMBs Struggle Spotting Scams

UK SMBs Struggle Spotting Scams

December 1, 2023
Honey Birdette Faces Data Breach

Honey Birdette Faces Data Breach

December 1, 2023

Latest Alerts

Zyxel Alerts Critical Flaws in NAS

Apple Tackles iOS Zero-Days

Hackers Deploy LUMMA via Invoice

UEFI Bugs Enable Bootkit Attacks

Fake Virus Alerts Hit Major Sites

FjordPhantom Targets Banks

Subscribe to our newsletter

    Latest Incidents

    Honey Birdette Faces Data Breach

    NC City Hit by Thanksgiving Hack

    Science History Institute Faces Ransomware

    Staples Faces Cyberattack

    Berglund’s Data Breach Hits 50K Individuals

    Cyber Attack Hits Capital

    Next Post

    48 Malicious npm Packages Uncovered

    • About Us
    • Contact Us
    • Legal and Privacy Policy
    • Site Map

    © 2023 | CyberMaterial | All rights reserved

    No Result
    View All Result
    • Alerts
    • Incidents
    • News
    • Cyber Briefing
    • Cyber Decoded
    • Cyber Hygiene
    • Cyber Review
    • Definitions
    • Malware
    • Cyber Tips
    • Tutorials

    Copyright © 2023 CyberMaterial

    Welcome Back!

    Login to your account below

    Forgotten Password?

    Retrieve your password

    Please enter your username or email address to reset your password.

    Log In

    Add New Playlist