Decrement by one to rule them all: AsIO3.sys driver exploitation
ID: f8f4f84b-d2e0-5760-90b5-514f33902636
STIX ID: report--f8f4f84b-d2e0-5760-90b5-514f33902636
Feed Name: Cisco Talos
This report details Talos's discovery and exploitation of critical vulnerabilities in the ASUS AsIO3.sys driver used by Armoury Crate: a stack-based buffer overflow in Win32-to-NT path conversion and an image-hash based authorization bypass. The researcher builds a local PoC exploit that achieves NT SYSTEM privileges by abusing a hardlink trick to pass the driver’s image-hash check, using an ObfDereferenceObject-based primitive to change a thread's PreviousMode, reading kernel memory to locate SYSTEM's EPROCESS and swapping its token; mitigations in Windows 11 24H2 limit some information leaks but the driver weaknesses remain high-risk for affected systems.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
