Process Explorer - ProcExp152.sys Driver Flagged As Vulnerable

Marc Denman 76 Reputation points
2022-08-31T17:36:54.77+00:00

Hello-

We are leveraging a new security solution in our environment that adds protection to our endpoints. The XDR solution has a rule that is detecting the driver ProcExp152.sys as being "vulnerable". I have asked our security vendor to better explain and was provided this explanation.

The driver load/write that is blocked by this rule is a driver that has a known vulnerability in it. an attacker can use this vulnerability to gain privilege escalation and (among other things) disable the XDR agent.

So my question is: Does this driver in fact contain a known vulnerability and if so, if there a newer version which was fixed?

Sysinternals
Sysinternals
Advanced system utilities to manage, troubleshoot, and diagnose Windows and Linux systems and applications.
1,260 questions
{count} votes

11 answers

Sort by: Most helpful
  1. Nick Westgate 1 Reputation point
    2024-08-13T01:12:03.87+00:00

    Does anyone have any further updates?

    I notice in the Microsoft recommended driver block rules they appear to block versions prior to the current major version (17 at the time of writing).

    <FileAttrib ID="ID_FILEATTRIB_PROCEXP" FriendlyName="Sysinternals Process Explorer FileAttribute" FileName="procexp.Sys" MinimumFileVersion="0.0.0.0" MaximumFileVersion="16.65535.65535.65535" />

    MS should really address this on the Process Explorer home page.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.