
Master's Thesis research on CVE-2024-51324 (BYOVD). Advanced exploit with 4 operational modes (SCANNER, LOADER, KILLER, CLEANUP), SHA-256 driver verification, and full academic documentation. Portfolio piece covers Windows kernel driver security, IOCTL reverse engineering, and Bring Your Own Vulnerable Driver exploitation.
Bring Your Own Vulnerable Driver (BYOVD) — Baidu Antivirus
BdApiUtil64.sys
Three undocumented kernel primitives: process termination, arbitrary file deletion, and in-use file deletion withSectionObjectPointerbypass
Affected: Baidu Antivirus v5.2.3.116083 (BdApiUtil64.sys)
Loading the vulnerable driver into kernel (LOADER mode)
This repository contains my Master's Thesis research on CVE-2024-51324, a
Bring Your Own Vulnerable Driver (BYOVD) vulnerability in Baidu Antivirus's kernel
driver BdApiUtil64.sys.
The NVD record assigns a CVSS v3.1 base score of 3.8 (Low) with vector
AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N and CWE-269 (Improper Privilege Management).
This score does not reflect the local attack reality documented in this research: once
the driver is loaded by an administrator (a one-time step achievable via social
engineering or any local privilege escalation), any subsequent process — including
sandboxed or standard-user processes — can send IOCTLs without further privilege checks.
A researcher-assessed CVSS v3.1 score of 7.8 (High) with vector
AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H more accurately captures the post-load
exploitation reality. Both scores are discussed in the technical documentation.
The driver creates the device object \Device\BdApiUtil with
SecurityDescriptor = NULL, allowing any process regardless of integrity level to open
a handle and send IOCTLs. Static analysis via Ghidra 11.0.3 reveals that the internal
mechanism is more significant than previously documented: the driver uses
PsLookupProcessByProcessId + ObOpenObjectByPointer(KernelMode) rather than
ZwOpenProcess, bypassing SeAccessCheck entirely. Three IOCTL primitives were fully
characterized, two of which have no prior public documentation.
| Aspect | Description |
|---|---|
| Technical correction | ZwOpenProcess is absent from the import table; the actual mechanism is PsLookupProcessByProcessId + ObOpenObjectByPointer(KernelMode), which bypasses SeAccessCheck unconditionally |
| Three documented primitives | Process termination (0x800024B4), arbitrary file deletion (0x80002648), and in-use file deletion with SectionObjectPointer bypass (0x8000264C) — the last two have no prior public documentation |
| Four operation modes | LOADER, KILLER, SCANNER, and CLEANUP — complete lifecycle management |
| SHA-256 verification | Driver hash verified before any load attempt |
| PPL empirical testing | 10 attempts per process category confirming PPL as the only runtime mitigation |
| Forensic analysis | Event ID 7045 persistence post-cleanup; Event ID 1102 as self-incriminating log-clear artifact |
| Detection rules | Sigma rule and Sysmon configuration (Event ID 6 by hash + Event ID 13 by registry key) |
| CVSS re-assessment | Documented discrepancy between official NVD score (3.8 Low) and researcher-assessed local exploitation severity (7.8 High) |
CVE-2024-51324/
├── README.md
├── LICENSE
│
├── drivers/
│ └── BdApiUtil64.sys # Driver (not distributed)
│
├── exploit/
│ ├── exploit-explanation.md
│ └── byovd_killer.py # Main exploit — 4 operational modes
│
└── docs/
├── screenshots/
│ ├── 01-byovd-scan.png
│ ├── 02-byovd-scan-target.png
│ ├── 03-byovd-load.png
│ ├── 04-byovd-load-custom.png
│ ├── 05-kill-name.gif
│ ├── 06-kill-pid.gif
│ ├── 07-kill-limit.gif
│ ├── 08-dry-run.gif
│ └── 09-byovd-cleanup.png
│
└── analysis/
├── 01-root-cause.md
├── 02-driver-analysis.md # Full Ghidra RE, three primitives, PPL testing
└── 03-timeline.md
BdApiUtil64.sys (SHA-256: 47EC51B5F0EDE1E70BD66F3F0152F9EB536D534565DBB7FCC3A05F542DBE4428)python exploit/byovd_killer.py --scan
python exploit/byovd_killer.py --scan --target lsass.exe
python exploit/byovd_killer.py --load
python exploit/byovd_killer.py --load --driver C:\path\to\BdApiUtil64.sys
python exploit/byovd_killer.py --load --service-name MyService
python exploit/byovd_killer.py --kill notepad.exe
python exploit/byovd_killer.py --pid 1234
python exploit/byovd_killer.py --kill notepad.exe --max-instances 2
python exploit/byovd_killer.py --kill notepad.exe --dry-run
python exploit/byovd_killer.py --cleanup
python exploit/byovd_killer.py --cleanup --service-name MyService
| Mode | Command | Privileges | Description |
|---|---|---|---|
| SCANNER | --scan | Any user | System and driver status information |
| LOADER | --load | Admin | Load driver via kernel service creation |
| KILLER | --kill / --pid | Any user | Terminate processes via IOCTL |
| CLEANUP | --cleanup | Admin | Stop and delete driver service |









Reverse engineering of BdApiUtil64.sys via Ghidra 11.0.3 identified a wider attack
surface than any prior public source documents: