Nil Hardware Editor Hardware Read & Write Utility Arbitrary Read/Write Vulnerability in HwRwDrv.sys

Vulnerability

A vulnerability in the HwRwDrv.sys component of Nil Hardware Editor Hardware Read & Write Utility, version 1.25.11.26 and earlier, allows attackers to perform arbitrary read and write operations. This is achieved through a crafted request, exploiting the driver's capability to manipulate Model Specific Registers (MSRs) and physical memory, both of which can lead to unauthorized execution of kernel-level code.

Impact

Exploitation of this vulnerability could result in unauthorized kernel code execution, potentially allowing an attacker to gain elevated privileges on the system.

Reproduction

To reproduce this vulnerability, place the vulnerable driver in the 'C:\Users\Public' directory. Then, run the exploit as an Administrator. The proof-of-concept (PoC) included in the GitHub repository demonstrates the vulnerability by swapping the primary token of the current process to gain 'NT Authority\SYSTEM' privileges.

Added: Mar 4, 2026, 5:30 PM
Updated: Mar 4, 2026, 6:23 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
4.0
remediation
0.0
relevance
3.5
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.