They discover the 'Screwed Drivers' vulnerability that affects all drivers and controllers from companies such as Intel, AMD, NVIDIA, ASUS and more.
And all hell broke loose. Last week, information was published about SWAPGS , a vulnerability affecting Intel processors and possibly Ryzen processors, although this is yet to be confirmed. Well, that pales in comparison to the vulnerability discovered by the cybersecurity research firm Eclypsium. The firm has dubbed it Screwed Drivers, and it affects the design of modern drivers from more than 40 manufacturers.
Screwed Drivers is a bug that allows malware to gain privileges from Ring 3 to Ring 0. Ring 0 basically grants access to all hardware without restrictions. Most seriously, it affects many hardware manufacturers who are Microsoft WHQL certified.
All drivers on the market are vulnerable due to a critical design flaw
Companies like Intel, AMD, NVIDIA, ASUS, Toshiba, SuperMicro, EVGA, MSI or Gigabyte, among others, are affected by Screwed Drivers. It not only affects driver designers, but also everyone who develops hardware monitoring or hardware management software. It affects all the software that in the Windows kernel can have access to the hardware with full privileges.
Eclypsium has found three types of privilege escalation in drivers. The first is RWEverything, followed by LoJax which allows installing malware in the UEFI and SlingShot. The vulnerability exploits the fact that Windows continues to work with drivers that have faulty, outdated or expired certificates.
Logically, the company has not explained in full detail how the vulnerability works, to prevent it from being exploited. Eclypsium is currently working with various manufacturers to develop mitigations and patches to fix it.
Note that these vulnerabilities are very serious, not because they steal data, but because they could destroy or disable systems. They could basically get access to the hardware and push it to the limit until it breaks.
So are the three Screwed Drivers vulnerabilities
- RWEverything: Allows access to all hardware interfaces through software. It operates in user space, but with a kernel-type driver signed RWDrv.sys installed only once. It is a hole that allows malware to gain access to Ring 0
- lojax: Use the RWDrv.sys library to access the SPI flash driver inside the chipset. Allows me to modify the UEFI BIOS of the motherboard.
- Sling Shot: An APT with a driver that contains malicious code that allows to exploit other MSR read / write drivers to bypass signature applications of the drivers installed through rootkit.
Source: TPU
