<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Byovd on HackingPassion.com : root@HackingPassion.com-[~]</title><link>https://hackingpassion.com/tags/byovd/</link><description>Recent content in Byovd on HackingPassion.com : root@HackingPassion.com-[~]</description><generator>Hugo</generator><language>en</language><lastBuildDate>Sat, 11 Jul 2026 13:01:35 +0200</lastBuildDate><atom:link href="https://hackingpassion.com/tags/byovd/index.xml" rel="self" type="application/rss+xml"/><item><title>Signed by Microsoft Does Not Mean Safe</title><link>https://hackingpassion.com/byovd-signed-driver-attacks/</link><pubDate>Sat, 11 Jul 2026 13:01:35 +0200</pubDate><guid>https://hackingpassion.com/byovd-signed-driver-attacks/</guid><description>&lt;p>A digital signature on a Windows driver proves who made it. &lt;strong>It was never proof that the driver is safe.&lt;/strong>
Attackers built a technique on that gap, called Bring Your Own Vulnerable Driver, and it hands them control of Windows at its deepest level. Some of the malware they use was signed through Microsoft&amp;rsquo;s own program.&lt;/p>
&lt;p>A driver is the piece of software that lets Windows and a device work together, your keyboard, your printer, your graphics card. It runs in the kernel, the core of the operating system, at a level called &lt;code>ring 0&lt;/code>, where code has direct access to memory and hardware. Security software mostly watches from a step below. Some of it runs inside the kernel too, but even that cannot protect itself once an attacker controls that level. &lt;strong>Reaching the kernel puts an attacker on top.&lt;/strong>&lt;/p></description></item><item><title>CVE-2023-31096: Microsoft Modem Driver Exploit Fixed Three Years Later</title><link>https://hackingpassion.com/cve-2023-31096-microsoft-modem-driver-exploit/</link><pubDate>Wed, 14 Jan 2026 15:11:28 +0100</pubDate><guid>https://hackingpassion.com/cve-2023-31096-microsoft-modem-driver-exploit/</guid><description>&lt;p>In January 2026, Microsoft had already patched 114 vulnerabilities! Four modem drivers deleted since October. Companies that wrote them: gone. Source code: inaccessible. Microsoft&amp;rsquo;s only option: remove them entirely. Meanwhile, ransomware groups are loading over 900 other vulnerable drivers that still ship with Windows. 😱 Hackers discovered they could use a 20-year-old telephone code to take over any Windows machine. No hardware required.&lt;/p>
&lt;p>One vulnerability stood out: CVE-2023-31096. A CVE number from 2023. Fixed in 2026. Three years later.&lt;/p></description></item></channel></rss>