Source: Help Net Security
Author: Mirko Zorz
URL: https://www.helpnetsecurity.com/2026/09/16/vulnerable-windows-drivers-deepzero-open-source/
https://www.helpnetsecurity.com/2026/09/16/vulnerable-windows-drivers-deepzero-open-source/
ONE SENTENCE SUMMARY:
DeepZero automates finding exploitable Windows kernel drivers using YAML pipelines, static analysis, filtering, and LLM exploitability assessment.
MAIN POINTS:
- DeepZero scans folders of Windows driver binaries to locate exploit candidates automatically.
- Project is open-source, written in Python 3.11+, with YAML-defined pipelines.
- Maintainer reports multiple verified vulnerabilities found in Snappy Driver Installer driver corpus.
- Included pipeline focuses on BYOVD attacks using signed but vulnerable kernel drivers.
- Stage one parses PE headers to extract metadata and initial driver characteristics.
- Stage two retains only kernel-mode drivers exposing reachable IOCTL interfaces.
- Stage three removes drivers already listed on loldrivers.io to avoid known cases.
- Ghidra headless decompilation and Semgrep rules analyze recovered/exported C-like output.
- A reduction step selects top candidates before sending artifacts to a language model.
- Hardware-dependent device creation can block confirmation without correct devices enumerated.
TAKEAWAYS:
- Layered filtering ensures the LLM reviews only high-signal, novel driver candidates.
- BYOVD remains practical because signed drivers can still contain exploitable flaws.
- Static reports may miss issues when device objects are created only via plug-and-play callbacks.
- Tracking IoCreateDevice location helps distinguish universally reachable drivers from hardware-gated ones.
- Framework is pipeline-oriented and can be adapted beyond Windows kernel driver analysis.