Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2024-51324 — Master's Thesis research on CVE-2024-51324 (BYOVD). Advanced exploit with 4 operational modes (SCANNER, LOADER, KILLER, CLEANUP), SHA-256 driver verification, and full academic documentation. Portfolio piece covers Windows kernel driver security, IOCTL reverse engineering, and Bring Your Own Vulnerable Driver exploitation. | Kitploit
Tools/GitHubGitHub/devianntsec/cve-2024-51324
Defensive ToolsVulnerability AnalysisExploitationReverse EngineeringForensicsPenetration TestingPapers & ResearchLearning & EducationRed Teaming

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Binary Exploitation
GitHubdevianntsec/cve-2024-51324

CVE-2024-51324

View Repository
1105 months agoNot yet reviewed

About

Master's Thesis research on CVE-2024-51324 (BYOVD). Advanced exploit with 4 operational modes (SCANNER, LOADER, KILLER, CLEANUP), SHA-256 driver verification, and full academic documentation. Portfolio piece covers Windows kernel driver security, IOCTL reverse engineering, and Bring Your Own Vulnerable Driver exploitation.

Share

CVE-2024-51324 — BYOVD: BdApiUtil64.sys · Master's Thesis Research

Platform Language License: MIT Research CVSS

Bring Your Own Vulnerable Driver (BYOVD) — Baidu Antivirus BdApiUtil64.sys
Three undocumented kernel primitives: process termination, arbitrary file deletion, and in-use file deletion with SectionObjectPointer bypass
Affected: Baidu Antivirus v5.2.3.116083 (BdApiUtil64.sys)


Loading the vulnerable driver into kernel (LOADER mode)

Description

This repository contains my Master's Thesis research on CVE-2024-51324, a Bring Your Own Vulnerable Driver (BYOVD) vulnerability in Baidu Antivirus's kernel driver BdApiUtil64.sys.

The NVD record assigns a CVSS v3.1 base score of 3.8 (Low) with vector AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N and CWE-269 (Improper Privilege Management). This score does not reflect the local attack reality documented in this research: once the driver is loaded by an administrator (a one-time step achievable via social engineering or any local privilege escalation), any subsequent process — including sandboxed or standard-user processes — can send IOCTLs without further privilege checks. A researcher-assessed CVSS v3.1 score of 7.8 (High) with vector AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H more accurately captures the post-load exploitation reality. Both scores are discussed in the technical documentation.

The driver creates the device object \Device\BdApiUtil with SecurityDescriptor = NULL, allowing any process regardless of integrity level to open a handle and send IOCTLs. Static analysis via Ghidra 11.0.3 reveals that the internal mechanism is more significant than previously documented: the driver uses PsLookupProcessByProcessId + ObOpenObjectByPointer(KernelMode) rather than ZwOpenProcess, bypassing SeAccessCheck entirely. Three IOCTL primitives were fully characterized, two of which have no prior public documentation.

My Contribution

AspectDescription
Technical correctionZwOpenProcess is absent from the import table; the actual mechanism is PsLookupProcessByProcessId + ObOpenObjectByPointer(KernelMode), which bypasses SeAccessCheck unconditionally
Three documented primitivesProcess termination (0x800024B4), arbitrary file deletion (0x80002648), and in-use file deletion with SectionObjectPointer bypass (0x8000264C) — the last two have no prior public documentation
Four operation modesLOADER, KILLER, SCANNER, and CLEANUP — complete lifecycle management
SHA-256 verificationDriver hash verified before any load attempt
PPL empirical testing10 attempts per process category confirming PPL as the only runtime mitigation
Forensic analysisEvent ID 7045 persistence post-cleanup; Event ID 1102 as self-incriminating log-clear artifact
Detection rulesSigma rule and Sysmon configuration (Event ID 6 by hash + Event ID 13 by registry key)
CVSS re-assessmentDocumented discrepancy between official NVD score (3.8 Low) and researcher-assessed local exploitation severity (7.8 High)

Repository Structure

CVE-2024-51324/
├── README.md
├── LICENSE
│
├── drivers/
│   └── BdApiUtil64.sys              # Driver (not distributed)
│
├── exploit/
│   ├── exploit-explanation.md
│   └── byovd_killer.py              # Main exploit — 4 operational modes
│
└── docs/
    ├── screenshots/
    │   ├── 01-byovd-scan.png
    │   ├── 02-byovd-scan-target.png
    │   ├── 03-byovd-load.png
    │   ├── 04-byovd-load-custom.png
    │   ├── 05-kill-name.gif
    │   ├── 06-kill-pid.gif
    │   ├── 07-kill-limit.gif
    │   ├── 08-dry-run.gif
    │   └── 09-byovd-cleanup.png
    │
    └── analysis/
        ├── 01-root-cause.md
        ├── 02-driver-analysis.md    # Full Ghidra RE, three primitives, PPL testing
        └── 03-timeline.md

Quick Start

Prerequisites

  • Windows 10/11 (any build)
  • Python 3.6+
  • BdApiUtil64.sys (SHA-256: 47EC51B5F0EDE1E70BD66F3F0152F9EB536D534565DBB7FCC3A05F542DBE4428)
  • Administrator account (LOADER and CLEANUP modes only)
  • Standard user account sufficient for KILLER mode once driver is loaded

Step 1 — Scan the system

python exploit/byovd_killer.py --scan
python exploit/byovd_killer.py --scan --target lsass.exe

Step 2 — Load the driver (Admin required)

python exploit/byovd_killer.py --load
python exploit/byovd_killer.py --load --driver C:\path\to\BdApiUtil64.sys
python exploit/byovd_killer.py --load --service-name MyService

Step 3 — Kill processes (No admin required)

python exploit/byovd_killer.py --kill notepad.exe
python exploit/byovd_killer.py --pid 1234
python exploit/byovd_killer.py --kill notepad.exe --max-instances 2
python exploit/byovd_killer.py --kill notepad.exe --dry-run

Step 4 — Cleanup (Admin required)

python exploit/byovd_killer.py --cleanup
python exploit/byovd_killer.py --cleanup --service-name MyService

Operational Modes

ModeCommandPrivilegesDescription
SCANNER--scanAny userSystem and driver status information
LOADER--loadAdminLoad driver via kernel service creation
KILLER--kill / --pidAny userTerminate processes via IOCTL
CLEANUP--cleanupAdminStop and delete driver service

Demonstrations

SCANNER Mode — System Information

SCANNER Mode

SCANNER Mode — Target Process Search

SCANNER Target

LOADER Mode — Loading Driver

LOADER Mode

LOADER Mode — Custom Path and Service Name

LOADER Custom

KILLER Mode — Kill by Process Name

Kill by Name

KILLER Mode — Kill by PID

Kill by PID

KILLER Mode — Limit Instances

Limit Instances

KILLER Mode — Dry Run (Simulation)

Dry Run

CLEANUP Mode — Unload Driver

CLEANUP Mode


Technical Overview

IOCTL Attack Surface — Three Primitives

Reverse engineering of BdApiUtil64.sys via Ghidra 11.0.3 identified a wider attack surface than any prior public source documents:

Download Tool