216.73.216.6

Legacy Driver Exploitation Through Bypassing Certificate Verification

· Published 18/03/2025 13:33 · Modified 18/03/2025 15:28

Export JSON

Essential information

Published
18/03/2025 13:33
Modified
18/03/2025 15:28
Tags
2025-03-18 CVE-2013-3900 avkiller certificate verification dll side-loading driver vulnerability gh0strat legacy driver exploitation padding manipulation truesight.sys
Related entities
3 observables, 7 techniques (mitre), 2 malware

Description

A new security threat using the technique has been identified, focusing on remote system control via malware. The attack distributes malware through phishing and messaging apps, utilizing for additional payloads. A modified driver bypasses Microsoft's driver blocking system, terminating security processes. The key vulnerability lies in versions 3.4.0 and below, exploited by the tool. The attacker manipulated the WIN_CERTIFICATE structure's padding area to bypass certificate validation. Microsoft responded by updating the Vulnerable Driver Blocklist. This technique is related to the vulnerability, highlighting the importance of strengthening certificate validation.

External references