Making Vulnerable Drivers Exploitable Without Hardware - The BYOVD Perspective
ID: 53ab7541-9057-5ef0-b61f-9b505bb0a01a
STIX ID: report--53ab7541-9057-5ef0-b61f-9b505bb0a01a
Feed Name: The Hacker News
This article analyzes how Windows kernel-mode drivers can be made reachable from user mode without the original hardware, explaining device object lifecycle (DriverEntry, AddDevice, IRP_MJ_PNP), hardware-gating patterns (MMIO, PCI, ACPI, DMA), and practical userland techniques — such as creating software-emulated devices via SetupAPI/SoftwareDevice, using devcon, filter restacking, and forced registry-based driver binding — that enable BYOVD-style attacks and the assessment of driver exploitability.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
