Researchers disclosed two signed Windows kernel drivers that can be abused in bring-your-own-vulnerable-driver (BYOVD) attacks to gain elevated privileges and bypass platform protections. Motorola's SmSerl64.sys from the SM56 Modem WDM Driver package (6.12.23.0) was reported as vulnerable to crafted IOCTL requests that let low-privileged users map physical memory, enabling privilege escalation, high-privilege code execution, and information disclosure; the issue is tracked as CVE-2024-55414. Separately, Patrick Saif reported that ComputerZ_x64.sys, shipped with Chengdu Qilu Technology's widely distributed Master Lu utility, exposes dangerous kernel primitives including arbitrary physical memory reads, unrestricted MSR reads that can defeat KASLR, weakly filtered port I/O, and unrestricted PCI configuration writes.
Both drivers are signed and therefore attractive for abuse on systems that enforce driver-signing requirements. The Master Lu driver reportedly is not on Microsoft's HVCI blocklist and can load on modern x64 Windows systems, while the Motorola driver has been added to LOLDrivers with recommendations to block SmSerl64.sys across endpoints and use published YARA and Sigma detections. In testing, the Master Lu proof of concept reportedly succeeded in loading the driver, accessing the device, reading IA32_LSTAR, reading physical memory, and performing PCI and port I/O operations, underscoring the risk that legitimate but vulnerable drivers can provide attackers with direct kernel-level capabilities.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
A public issue documented that ComputerZ_x64.sys was code signed, not on the HVCI blocklist or LOLDrivers, and could be abused for BYOVD on modern x64 Windows systems. The researcher said proof-of-concept testing passed all 10 checks, confirming the exposed capabilities and abuse potential.
Patrick Saif reported a vulnerable signed Windows kernel driver, ComputerZ_x64.sys from Master Lu, to the vendor and submitted a MITRE CVE request. The report said the driver exposed dangerous kernel primitives including physical memory read, MSR read, PCI configuration access, and port I/O.
A GitHub repository published technical details and exploit code for CVE-2025-7771 in ThrottleStop.sys, describing unrestricted IOCTL access that allows mapping physical memory via MmMapIoSpace. The issue enables local privilege escalation and adds another signed driver to the BYOVD abuse landscape.
LOLDrivers published an entry for Motorola's signed SmSerl64.sys driver, describing a flaw that lets low-privileged users map physical memory via crafted IOCTLs. The listing said the issue could enable privilege escalation, code execution, information disclosure, and abuse of the signed driver to bypass Microsoft's driver-signing policy, and included detection and blocking guidance.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
loldrivers.io
Open sourcegithub.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.