logo

Exploring vulnerable Windows drivers

ID: 8a525a65-2c42-5676-8b44-8ff697fdd624

STIX ID: report--8a525a65-2c42-5676-8b44-8ff697fdd624

Feed Name: Cisco Talos

Threat Score
75/100

Date Published: 2024-12-19

Date Updated: 2026-04-27

Author: Vanja Svajcer

...
...

This research overview examines the Bring Your Own Vulnerable Driver (BYOVD) technique: how legacy or poorly-permissioned signed drivers are abused to perform kernel-level actions (token stealing for privilege escalation, loading unsigned code, and disabling EDR/anti-cheat). It categorizes common driver vulnerability classes (arbitrary MSR writes, arbitrary kernel memory read/write, insufficient access controls), documents multiple 2024 ransomware campaigns and malware (Kasseika, Akira, Qilin, BlackByte, RansomHub, Gh0stRAT examples) that abused specific drivers and open-source tools to bypass protections, and recommends mitigations such as enabling HVCI/VBS, using driver blocklists, enforcing EV/WHQL drivers, and monitoring driver load events.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.