GeistHaus
log in ยท sign up

BYOVD to the next level (part 1) โ€” exploiting a vulnerable driver (CVE-2025-8061)

blog.quarkslab.com

Bring Your Own Vulnerable Driver (BYOVD) is a well-known post-exploitation technique used by adversaries. This blog post is part of a series. We will see how to abuse a vulnerable driver to gain access to Ring-0 capabilities. In this first post we describe in detail the exploitation of vulnerabilities found in a signed Lenovo driver on Windows.

2 pages link to this URL
Last Week in Security (LWiS) - 2025-09-29

OmniProx (@ZephrFish), Phantom Chrome Extensions (Riadh Bouchahoua (@Synacktiv)), FIDO phishing (@dennis_kniep), VMWare Tools LPE (@0xThiebaut), MSI lateral movement (@werdhaihai), and more!

0 inbound links article en