logo

g_CiOptions in a Virtualized World

ID: 358cf5bd-7098-561f-aeb8-4bcda1bd5862

STIX ID: report--358cf5bd-7098-561f-aeb8-4bcda1bd5862

Feed Name: TrustedSec blog

Threat Score
75/100

Date Published: 2025-03-25

Date Updated: 2026-05-01

...
...

This report analyzes methods for bypassing Windows Driver Signature Enforcement (DSE) to load unsigned kernel drivers—either by patching CI.dll's CiValidateImageHeader through direct PTE manipulation or by using vulnerable signed drivers (e.g., iqvw64e.sys) to achieve kernel read/write primitives. It shows how Kernel Data Protection (KDP) under VBS can block simple g_CiOptions overwrites, provides signature-hunting and PTE-modification PoC code to patch executable kernel pages, and explains that enabling HVCI (SLAT-enforced protections) or Attack Surface Reduction can mitigate these attacks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.