Slide 25
Slide 25 text
RESULT
• 34 unique vulnerable drivers (237 file hashes) allowing
firmware access
• 30 WDM, 4 WDF
• Intel, AMD, Phoenix Tech, GE, IBM, Avast, DELL, NVIDIA, Realtek,
Samsung, OMRON, etc.
• All drivers give full control of the devices to non-admin users
• I could load most drivers on HVCI-enabled Win11 except five
• Other arbitrary R/W vulnerabilities
• Kernel VA (6), MSR (12), CR (3), registry key/value (2)
• I reported vendors whose drivers had valid signatures
• Only two vendors fixed then assigned the CVEs
• CVE-2023-35841 and CVE-2023-20598
2/22/2024 Vulnerable Driver Demo 26