logo

Breaking Boundaries: Investigating Vulnerable Drivers and Mitigating Risks

ID: 55c90864-a6b1-5422-a288-a81fbf3c0dc0

STIX ID: report--55c90864-a6b1-5422-a288-a81fbf3c0dc0

Feed Name: Check Point Research

Threat Score
78/100

Date Published: 2024-09-30

Date Updated: 2026-04-27

Author: [email protected]

...
...

Check Point Research analysed common design flaws in 64-bit Windows kernel drivers that allow non-privileged users to cross the user→kernel security boundary, built YARA-based mass-hunt tooling (VT Retrohunt) that identified thousands of at-risk signed drivers, and demonstrated a practical exploit chain against a Dr.Web anti-rootkit driver leading to local privilege escalation, arbitrary kernel/user memory R/W, and process termination; the report provides PoCs, hashes, mitigation guidance (use IoCreateDeviceSecure, set strong DACL and FILE_DEVICE_SECURE_OPEN), and discusses limitations of existing mitigations such as Microsoft’s blocklist.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.