Le vulnerabilità del firmware e dei driver continuano a esporre percorsi di abuso del kernel e della memoria fisica
Several low-level vulnerabilities showed how drivers and firmware can grant attackers dangerous kernel capabilities. CERT published a Pegatron tdeio64.sys issue that allowed arbitrary kernel read and write through an unprotected IOCTL interface, and another report covered ASUS bsitf.sys enabling physical-memory mapping via unvalidated IOCTLs. A Realtek driver flaw similarly allowed DMA controller abuse from user mode, showing that vendor-supplied hardware components can undermine system boundaries. These flaws matter because once an attacker gets kernel-level access, EDR bypass, credential theft, persistence, and rootkit installation become much easier. Firmware and driver issues are especially risky because they often survive ordinary reinstallation or are trusted by the operating system. The takeaway is that platform vendors still ship code with extremely powerful privileges and incomplete validation.
Fonti
- VU#529388: Vulnerabilità di escalation dei privilegi tramite interfaccia IOCTL non protetta in Pegatron Tdelo64.sys — CERT Vulnerability Notes
- ASUS bsitf.sys (CVE-2026-13585): mappatura arbitraria della memoria fisica tramite IOCTL non convalidati — /r/netsec
- Una vulnerabilità nel driver Realtek consente l’abuso del controller DMA dalla modalità utente senza hardware o driver aggiuntivi — /r/netsec
- Prova di concetto per CVE-2026-58635 LPE nel servizio Windows Braille Narrator — /r/cybersecurity


Lascia un commento