Elastic Security Labs warned that ransomware operators increasingly use legitimately signed but vulnerable Windows drivers to gain kernel-mode execution, tamper with endpoint defenses, and encrypt systems. The researchers identified an unrestricted handle-duplication flaw in the Microsoft Sysinternals Process Explorer driver that a user-mode attacker could exploit to access raw physical memory, enabling arbitrary kernel read/write operations or kernel code execution.
Organizations should treat vulnerable signed drivers as a high-risk attack path and block known-abused drivers before they load. Elastic recommends combining vulnerable-driver blocklists, Windows Defender Application Control (WDAC) driver allowlisting, behavioral protections, and monitoring for first-seen or anomalous driver loads; Elastic Endpoint 8.3 and later validates drivers against its blocklist prior to loading.

Get the actors, campaigns, and ATT&CK mapping behind it.
4 events from the most recent confirmed update back to the earliest known activity.
Elastic disclosed that Process Explorer's driver can duplicate a raw physical-memory handle from the Windows System process, enabling arbitrary kernel memory read/write primitives and potentially kernel code execution.
Elastic Security released 65 community-available YARA rules intended to detect abuse of vulnerable Windows drivers, a technique used by ransomware operators to obtain kernel-mode execution and disable security products.
Elastic reported the unrestricted handle-duplication vulnerability in Microsoft Process Explorer's driver through Microsoft's vulnerable-driver submission portal on July 26. Elastic said it had not received a response at the time of writing.
Microsoft had previously blocked the ProcessHacker (now System Informer) driver because of the same unrestricted handle-duplication flaw described in the Process Explorer driver.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.