PCTCore64.sys driver from discontinued PC Tools Internet Security enables BYOVD attacks…
PCTCore64.sys driver from discontinued PC Tools Internet Security enables BYOVD attacks for credential theft and process termination via exposed IOCTL interface.
The PCTCore64.sys Windows kernel driver from the discontinued PC Tools Internet Security product exposes its device interface without access control, allowing any user-mode process to invoke privileged IOCTL commands. Despite the product being discontinued in 2013, the signed driver remains exploitable in Bring Your Own Vulnerable Driver (BYOVD) attacks. Local attackers with driver-loading capability can leverage exposed IOCTL handlers to perform system-wide handle enumeration, cross-process handle manipulation, credential extraction from lsass.exe, and forced termination of Protected Process Light (PPL)-protected processes including security software.
The vulnerability enables practical attack paths for credential theft through acquisition of PROCESS_ALL_ACCESS handles to sensitive processes, extraction of NTLM hashes and Kerberos authentication material, and defense evasion via termination of Microsoft Defender and other security services. Additional exposed interfaces permit arbitrary handle operations against external processes, potentially causing system instability. The driver's lack of security descriptor implementation via SDDL or IoCreateDeviceSecure API allows unprivileged processes to open handles and issue privileged requests.
Organizations should remove and block the vulnerable driver, implement Microsoft recommended driver block rules, and enable protections including Hypervisor-Protected Code Integrity (HVCI), Windows Defender Application Control (WDAC), and Credential Guard. Administrative privileges should be restricted to limit BYOVD attack surface.
Mentioned in this report
Source reporting: https://kb.cert.org/vuls/id/158530
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free