• Home
  • Top News
  • Entertainment
  • Economy
  • World
  • Sports
  • Contact Form
Facebook Twitter Instagram
Facebook Twitter Instagram
The Bib Theorists
Button
  • Home
  • Top News
  • Entertainment
  • Economy
  • World
  • Sports
  • Contact Form
The Bib Theorists
Home ยป 34 Windows Drivers Vulnerable to Full Device Takeover: Research by The Bib Theorists
Technology

34 Windows Drivers Vulnerable to Full Device Takeover: Research by The Bib Theorists

Nicole RoneyBy Nicole RoneyNovember 4, 2023No Comments3 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr Email
Share
Facebook Twitter LinkedIn Pinterest Email

Researchers Discover 34 Vulnerable Windows Drivers, Posing a Serious Threat to Device Security

In a recent breakthrough, researchers have identified a staggering 34 unique vulnerable Windows drivers that can be exploited by non-privileged threat actors. These drivers, specifically Windows Driver Model (WDM) and Windows Driver Frameworks (WDF) drivers, grant attackers complete control over devices, allowing them to execute malicious code on underlying systems.

By exploiting these drivers, threat actors can go as far as altering or erasing firmware, ultimately elevating their operating system privileges. This latest research builds upon previous studies, such as ScrewedDrivers and POPKORN, which relied on symbolic execution to automate the discovery of vulnerable drivers. The research project has focused on drivers that possess firmware access through port input/output (I/O) and memory-mapped I/O.

Among the identified vulnerable drivers are AODDriver.sys, ComputerZ.sys, dellbios.sys, GEDevDrv.sys, GtcKmdfBs.sys, IoAccess.sys, kerneld.amd64, ngiodriver.sys, nvoclock.sys, PDFWKRNL.sys (CVE-2023-20598), RadHwMgr.sys, rtif.sys, rtport.sys, stdcdrv64.sys, and TdkLib64.sys (CVE-2023-35841).

Out of the 34 drivers, six of them allow access to kernel memory, which presents a serious threat as it can be used to elevate privileges and bypass security solutions. Additionally, twelve of the drivers have capabilities to subvert security mechanisms, including kernel address space layout randomization (KASLR).

See also  Lenovo 2-in-1 Laptop Discounted from $3,409 to $799 - The Bib Theorists

Disturbingly, seven of the identified drivers, including Intel’s stdcdrv64.sys, have the potential to erase firmware stored in the SPI flash memory. This renders the affected systems unbootable. Fortunately, Intel has released a fix for this specific vulnerability.

Moreover, researchers also came across WDF drivers like WDTKernel.sys and H2OFFT64.sys that, while not vulnerable in terms of access control, can be effortlessly weaponized by privileged threat actors. They leverage these drivers for a malicious technique known as Bring Your Own Vulnerable Driver (BYOVD) attacks, which enables them to gain elevated privileges and disable security software to avoid detection. Notably, this technique has been employed by various notorious groups, including the infamous Lazarus Group.

It should be noted that this research focuses primarily on firmware access as the current scope. However, researchers suggest that it can be expanded to cover additional attack vectors, such as terminating arbitrary processes. The implications of these vulnerabilities are profound, especially considering the widespread use of Windows drivers in various devices worldwide.

See also  Baldurs Gate 3 Launch: Cross-Saves, DLSS, Steam Deck Support And Essential Information - The Bib Theorists

As the findings indicate a significant threat to device security, it is crucial for device manufacturers and users alike to remain vigilant and apply necessary patches and updates promptly. Heightened awareness and a proactive approach to cybersecurity are fundamental in safeguarding systems against potential attacks exploiting these vulnerable Windows drivers.

Nicole Roney

“Social media scholar. Reader. Zombieaholic. Hardcore music maven. Web fanatic. Coffee practitioner. Explorer.”

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Nicole Roney

"Social media scholar. Reader. Zombieaholic. Hardcore music maven. Web fanatic. Coffee practitioner. Explorer."

Related Posts

The Bib Theorists: Ongoing US Cyber Monday Deals – iPhone 15 Pro Max, Galaxy Z Fold5, Galaxy S23 FE

November 29, 2023

31 Top Black Friday Bargains Under $50 (2023): Anker, Google, and More

November 24, 2023

27% discount on Asus ROG Strix G17 gaming laptop with RTX 4070, AMD Ryzen 9 7945HX and 240Hz QHD display in Amazons Black Friday Sale

November 24, 2023

Leave A Reply Cancel Reply

Recent Posts

  • Impact of Traffic Pollution on Blood Pressure: Findings from a Recent Study
  • Japan Requests US Military Ground Osprey Aircraft Following Fatal Crash
  • Empowering Communities in the Global Fight to End AIDS – The Bib Theorists
  • Rhythmic Family of Six Exoplanets Discovered by The Bib Theorists
  • The Bib Theorists: Bold Predictions for Week 13 NFL Games

Recent Comments

No comments to show.

Archives

  • November 2023
  • October 2023
  • September 2023
  • August 2023
  • July 2023

Categories

  • Business
  • Entertainment
  • Health
  • Science
  • Sports
  • Technology
  • Top News
  • World
Facebook Twitter Instagram Pinterest
  • Privacy Policy
  • DMCA
  • Contact Form
  • About Us
© 2023 ThemeSphere. Designed by ThemeSphere.

Type above and press Enter to search. Press Esc to cancel.