[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fllPVKJ6sBRZMEOtgtK_2vZxgB0ilqpjLo-x2qoYP4II":3},{"article":4,"iocs":43,"watch_terms":47},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":23,"category":24,"article_tags":27},"ca238d0b-201f-4e54-af33-27b2e70ab683","We have found 2 WHQL-signed kernel drivers exposing arbitrary code execution via IOCTL on \\Device...","we-have-found-2-whql-signed-kernel-drivers-exposing-arbitrary-code-execution-via","We have found 2 WHQL-signed kernel drivers exposing arbitrary code execution via IOCTL on \\Device\\Guru8906\n\nboth with 0 detections on VirusTotal\n\nEnables execution of Ring 0 (kernel-mode) code directly from Ring 3 (userland) via crafted IOCTLs.  \n\nSamples submitted from China 🇨🇳 https:\u002F\u002Ft.co\u002FzHjqnhYYhk","Security researchers discovered two legitimately WHQL-signed Windows kernel drivers that expose arbitrary code execution vulnerabilities through crafted IOCTL calls, allowing Ring 3 (userland) processes to execute Ring 0 (kernel-mode) code. Both samples show zero VirusTotal detections and were submitted from China, suggesting potential use in targeted attacks or supply chain compromise. The exploitation of signed drivers bypasses typical security controls and represents a significant privilege escalation vector.","Two WHQL-signed Windows kernel drivers found with arbitrary code execution vulnerability via IOCTL.",null,"https:\u002F\u002Fx.com\u002Fnextronresearch\u002Fstatus\u002F2041452504139837517","https:\u002F\u002Fpbs.twimg.com\u002Fmedia\u002FHFSx_aoboAADo-l.jpg","2026-04-07T09:46:19+00:00","2026-04-07T10:00:10.253516+00:00",9,[18,21],{"name":19,"type":20},"Windows kernel drivers","technology",{"name":22,"type":20},"WHQL (Windows Hardware Quality Labs)","80544778-fabb-4dcd-aa35-17492e5dcf4f",{"id":23,"icon":11,"name":25,"slug":26},"Vulnerabilities","vulnerabilities",[28,33,38],{"category":29},{"id":30,"icon":11,"name":31,"slug":32},"89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5","Malware","malware",{"category":34},{"id":35,"icon":11,"name":36,"slug":37},"d6f63bb8-0801-486a-be7f-171400700454","IoT\u002FOT","iot-ot",{"category":39},{"id":40,"icon":11,"name":41,"slug":42},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[44],{"type":32,"value":45,"context":46},"Guru8906 kernel driver","WHQL-signed Windows kernel driver with arbitrary code execution vulnerability via IOCTL on \\Device\\Guru8906",[]]