-
Notifications
You must be signed in to change notification settings - Fork 133
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Request to add vulnerable driver BdApiUtil.sys (CVE-2024-51324) #204
Comments
Can I get .sys file? |
I think this will work, hopefully it attaches okay |
Ah, thank you. Sorry, I must have grabbed a different version, I've updated the link. I appreciate it |
hey all, i know this isnt the correct place for this but i do need help with getting a .sys vulnerable gdrv file. the ones i have downloaded were extracted in hex and im not too sure if they work, anyone here have the download to the actual .sys file? |
If you downloaded it from loldrivers.io just change name from .bin to .sys and create service type kernel and run it, this is what you mean? |
Was hoping to get BdApiUtil.sys added to this as a vulnerable driver. I wasn't sure the best place to do that, so opened an issue.
Summary:
I found an IOCTL code which takes a PID and terminates it (arbitrary process termination). Admin privileges required to install the driver, but if it's already installed, can be called by any user (non admin).
Here's the specific version I tested against in VT (likely other versions vulnerable too):
http://virustotal.com/gui/file/32198295d2a2700b9895fff999c2b233f9befb0bc175815ec4b71ee926b6edfc
IOCTL needed is 0x800024B4
PoC:
The text was updated successfully, but these errors were encountered: