Breaking Boundaries: Investigating Vulnerable Drivers and Mitigating Risks
ID: 55c90864-a6b1-5422-a288-a81fbf3c0dc0
STIX ID: report--55c90864-a6b1-5422-a288-a81fbf3c0dc0
Feed Name: Check Point Research
Check Point Research analysed common design flaws in 64-bit Windows kernel drivers that allow non-privileged users to cross the user→kernel security boundary, built YARA-based mass-hunt tooling (VT Retrohunt) that identified thousands of at-risk signed drivers, and demonstrated a practical exploit chain against a Dr.Web anti-rootkit driver leading to local privilege escalation, arbitrary kernel/user memory R/W, and process termination; the report provides PoCs, hashes, mitigation guidance (use IoCreateDeviceSecure, set strong DACL and FILE_DEVICE_SECURE_OPEN), and discusses limitations of existing mitigations such as Microsoft’s blocklist.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
