LOLDrivers Database
Vulnerable and malicious Windows drivers database
Last updated: Loading...
Changes apply when you click Apply Filters. Live search activates as you type.
PhantomKiller
x64LENOVO · 2018-01-03
DescriptionPhantomKiller is the newly released, featured process-killer variant based on Lenovo BootRepair.sys. It is tracked separately from the base BootRepair entry: the project ships it as PhantomKiller.sys, while the underlying vulnerable driver lineage is BootRepair.sys from Lenovo PC Manager. The driver exposes \\.\BootRepair without secure DACL restrictions and accepts IOCTL 0x222014 with a 4-byte PID, then calls PsLookupProcessByProcessId, ObOpenObjectByPointer, and ZwTerminateProcess to terminate protected EDR/AV processes.
Operating System
Windows x64
Privileges
Driver load requires administrative privileges; an already loaded driver can be abused by a low-privileged user according to the project README.
Use Case
BYOVD process termination against EDR/AV protected processes.
Command
sc.exe create PhantomKiller binPath="C:\Path\to\PhantomKiller.sys" type=kernel
sc.exe start PhantomKiller
PhantomKiller.exe <pid>biontdrv.sys
x64Paragon Software GmbH · 2025-03-02
DescriptionMicrosoft has identified five security flaws in the Paragon Partition Manager BioNTdrv.sys driver, one of which was exploited by ransomware gangs in zero-day attacks to gain SYSTEM privileges on Windows systems. These vulnerabilities, found in BioNTdrv.sys versions 1.3.0 and 1.5.1, enable attackers to escalate their privileges to SYSTEM level to a higher access level than standard administrator permissions.
Operating System
Windows 10
Privileges
kernel
Use Case
Elevate privileges
Command
sc.exe create BioNTdrv.sys binPath=C:\windows\temp\BioNTdrv.sys type=kernel && sc.exe start BioNTdrv.sysbiontdrv.sys
x64Paragon Software GmbH · 2025-03-02
DescriptionMicrosoft has identified five security flaws in the Paragon Partition Manager BioNTdrv.sys driver, one of which was exploited by ransomware gangs in zero-day attacks to gain SYSTEM privileges on Windows systems. These vulnerabilities, found in BioNTdrv.sys versions 1.3.0 and 1.5.1, enable attackers to escalate their privileges to SYSTEM level to a higher access level than standard administrator permissions.
Operating System
Windows 10
Privileges
kernel
Use Case
Elevate privileges
Command
sc.exe create BioNTdrv.sys binPath=C:\windows\temp\BioNTdrv.sys type=kernel && sc.exe start BioNTdrv.sysSBIOSIO64.sys
x32Windows (R) Win 7 DDK provider · 2023-11-02
DescriptionThe Carbon Black Threat Analysis Unit (TAU) discovered 34 unique vulnerable drivers (237 file hashes) accepting firmware access. Six allow kernel memory access. All give full control of the devices to non-admin users. By exploiting the vulnerable drivers, an attacker without the system privilege may erase/alter firmware, and/or elevate privileges. As of the time of writing in October 2023, the filenames of the vulnerable drivers have not been made public until now.
Operating System
Windows 10
Privileges
kernel
Use Case
Elevate privileges
Command
sc.exe create SBIOSIO64sys binPath= C:\windows\temp\SBIOSIO64sys.sys type=kernel && sc.exe start SBIOSIO64sysSBIOSIO64.sys
x64Windows (R) Win 7 DDK provider · 2023-11-02
DescriptionThe Carbon Black Threat Analysis Unit (TAU) discovered 34 unique vulnerable drivers (237 file hashes) accepting firmware access. Six allow kernel memory access. All give full control of the devices to non-admin users. By exploiting the vulnerable drivers, an attacker without the system privilege may erase/alter firmware, and/or elevate privileges. As of the time of writing in October 2023, the filenames of the vulnerable drivers have not been made public until now.
Operating System
Windows 10
Privileges
kernel
Use Case
Elevate privileges
Command
sc.exe create SBIOSIO64sys binPath= C:\windows\temp\SBIOSIO64sys.sys type=kernel && sc.exe start SBIOSIO64sysSBIOSIO64.sys
x64Windows (R) Win 7 DDK provider · 2023-11-02
DescriptionThe Carbon Black Threat Analysis Unit (TAU) discovered 34 unique vulnerable drivers (237 file hashes) accepting firmware access. Six allow kernel memory access. All give full control of the devices to non-admin users. By exploiting the vulnerable drivers, an attacker without the system privilege may erase/alter firmware, and/or elevate privileges. As of the time of writing in October 2023, the filenames of the vulnerable drivers have not been made public until now.
Operating System
Windows 10
Privileges
kernel
Use Case
Elevate privileges
Command
sc.exe create SBIOSIO64sys binPath= C:\windows\temp\SBIOSIO64sys.sys type=kernel && sc.exe start SBIOSIO64sysSBIOSIO64.sys
x32Windows (R) Win 7 DDK provider · 2023-11-02
DescriptionThe Carbon Black Threat Analysis Unit (TAU) discovered 34 unique vulnerable drivers (237 file hashes) accepting firmware access. Six allow kernel memory access. All give full control of the devices to non-admin users. By exploiting the vulnerable drivers, an attacker without the system privilege may erase/alter firmware, and/or elevate privileges. As of the time of writing in October 2023, the filenames of the vulnerable drivers have not been made public until now.
Operating System
Windows 10
Privileges
kernel
Use Case
Elevate privileges
Command
sc.exe create SBIOSIO64sys binPath= C:\windows\temp\SBIOSIO64sys.sys type=kernel && sc.exe start SBIOSIO64sysLgCoreTemp.sys
x64Logitech · 2023-04-15
DescriptionCPU Core Temperature Monitor
Operating System
Windows 10
Privileges
kernel
Use Case
Denial of Service
Command
sc.exe create LgCoreTemp.sys binPath=C:\windows\temp\LgCoreTemp.sys type=kernel && sc.exe start LgCoreTemp.sysLgCoreTemp.sys
x32Logitech · 2023-04-15
DescriptionCPU Core Temperature Monitor
Operating System
Windows 10
Privileges
kernel
Use Case
Denial of Service
Command
sc.exe create LgCoreTemp.sys binPath=C:\windows\temp\LgCoreTemp.sys type=kernel && sc.exe start LgCoreTemp.sysnt3.sys
2023-01-09
Operating System
Windows 10
Privileges
kernel
Use Case
Elevate privileges
Command
sc.exe create nt3.sys binPath=C:\windows\temp \n \n \n t3.sys type=kernel && sc.exe start nt3.sysNo imported functions
CmUpx
x64Realtek Semiconductor Corp. · 2026-04-17
DescriptionCmUpx.sys is a vulnerable kernel driver from the KeServiceDescriptorTable/vulnerable-drivers repository. The driver exposes dangerous kernel primitives to usermode.
Operating System
Windows 10
Privileges
kernel
Use Case
Elevate privileges
Command
sc.exe create CmUpx binPath=C:\windows\temp\CmUpx.sys type=kernel && sc.exe start CmUpxMy.sys
2023-01-09
Operating System
Windows 10
Privileges
kernel
Use Case
Elevate privileges
Command
sc.exe create My.sys binPath=C:\windows\temp\My.sys type=kernel && sc.exe start My.sysNo imported functions
WinFlash64.sys
x642023-01-09
Operating System
Windows 10
Privileges
kernel
Use Case
Elevate privileges
Command
sc.exe create WinFlash64.sys binPath=C:\windows\temp\WinFlash64.sys type=kernel && sc.exe start WinFlash64.sysTRIXX.sys
x642026-04-07
DescriptionTRIXX.sys is a shared utility kernel driver distributed by TechPowerUp LLC with Sapphire TRIXX and GPU-Z. The driver provides completely unrestricted hardware access from usermode through 16+ IOCTLs with zero validation on hardware parameters, including arbitrary port I/O read/write, arbitrary PCI configuration space read/write via HalGetBusDataByOffset/HalSetBusDataByOffset, MMIO BAR mapping via MmMapIoSpace, and MMIO read/write through mapped BARs. Physical memory read/write is achievable by remapping a PCI device BAR to a target physical address then mapping it via MmMapIoSpace. The driver creates its device dynamically based on the Windows service name and has no hardware dependency, loading on any x64 Windows system. TechPowerUp has a history of vulnerable kernel drivers including GPU-Z.sys (CVE-2019-7245, CVE-2025-5324) and ThrottleStop.sys (CVE-2025-7771) which expose the same MmMapIoSpace primitive. Fresh EV code signing certificate valid until April 2028 with zero AV detections.
Operating System
Windows 10
Privileges
kernel
Use Case
Elevate privileges
Command
sc.exe create TRIXX binPath=C:\windows\temp\TRIXX.sys type=kernel && sc.exe start TRIXXTRIXX.sys
x322026-04-07
DescriptionTRIXX.sys is a shared utility kernel driver distributed by TechPowerUp LLC with Sapphire TRIXX and GPU-Z. The driver provides completely unrestricted hardware access from usermode through 16+ IOCTLs with zero validation on hardware parameters, including arbitrary port I/O read/write, arbitrary PCI configuration space read/write via HalGetBusDataByOffset/HalSetBusDataByOffset, MMIO BAR mapping via MmMapIoSpace, and MMIO read/write through mapped BARs. Physical memory read/write is achievable by remapping a PCI device BAR to a target physical address then mapping it via MmMapIoSpace. The driver creates its device dynamically based on the Windows service name and has no hardware dependency, loading on any x64 Windows system. TechPowerUp has a history of vulnerable kernel drivers including GPU-Z.sys (CVE-2019-7245, CVE-2025-5324) and ThrottleStop.sys (CVE-2025-7771) which expose the same MmMapIoSpace primitive. Fresh EV code signing certificate valid until April 2028 with zero AV detections.
Operating System
Windows 10
Privileges
kernel
Use Case
Elevate privileges
Command
sc.exe create TRIXX binPath=C:\windows\temp\TRIXX.sys type=kernel && sc.exe start TRIXXTRIXX.sys
x322026-04-07
DescriptionTRIXX.sys is a shared utility kernel driver distributed by TechPowerUp LLC with Sapphire TRIXX and GPU-Z. The driver provides completely unrestricted hardware access from usermode through 16+ IOCTLs with zero validation on hardware parameters, including arbitrary port I/O read/write, arbitrary PCI configuration space read/write via HalGetBusDataByOffset/HalSetBusDataByOffset, MMIO BAR mapping via MmMapIoSpace, and MMIO read/write through mapped BARs. Physical memory read/write is achievable by remapping a PCI device BAR to a target physical address then mapping it via MmMapIoSpace. The driver creates its device dynamically based on the Windows service name and has no hardware dependency, loading on any x64 Windows system. TechPowerUp has a history of vulnerable kernel drivers including GPU-Z.sys (CVE-2019-7245, CVE-2025-5324) and ThrottleStop.sys (CVE-2025-7771) which expose the same MmMapIoSpace primitive. Fresh EV code signing certificate valid until April 2028 with zero AV detections.
Operating System
Windows 10
Privileges
kernel
Use Case
Elevate privileges
Command
sc.exe create TRIXX binPath=C:\windows\temp\TRIXX.sys type=kernel && sc.exe start TRIXXTPwSav.sys
x64Compal Electronic, Inc. · 2025-01-31
DescriptionA driver associated with Toshiba laptops power saving functionality allows arbitary one byte reading and writing mapped physical addresses. Blackpoint Cyber's SOC observed this driver being used as part of a custom EDRSandblast malware to blind EDR prior to Qilin ransomware deployment.
Operating System
Windows
Privileges
kernel
Use Case
Elevate privileges, Blind EDR
Command
sc.exe create TPwSav.sys binPath=C:\windows\temp\TPwSav.sys type=kernel && sc.exe start TPwSav.sysbwrsh.sys
2023-01-09
Operating System
Windows 10
Privileges
kernel
Use Case
Elevate privileges
Command
sc.exe create bwrsh.sys binPath=C:\windows\temp\bwrsh.sys type=kernel && sc.exe start bwrsh.sysNo imported functions
rtcoremini64.sys
x642023-07-22
DescriptionConfirmed vulnerable driver from Microsoft Block List
Operating System
Windows
Privileges
kernel
Use Case
Elevate privileges
vmdrv.sys
x64Windows (R) Win 7 DDK provider · 2023-05-06
DescriptionVoicemod Virtual Audio Device (WDM)
Operating System
Windows 10
Privileges
kernel
Use Case
Elevate privileges
Command
sc.exe create vmdrv.sys binPath=C:\windows\temp\vmdrv.sys type=kernel && sc.exe start vmdrv.sys