Netwtw14.sys - Vulnerable (72/100) - DriverShield Analysis

Analysis of Netwtw14.sys: vulnerable verdict, risk score 72/100. 0 YARA matches, 0/76 multi-engine detections. SHA256 660ef8f59f3b2ff0. Kernel imports, IOCTL codes, MITRE ATT&CK, and code-signing details.

Netwtw14.sys - Analysis Report

DriverShield analyzed the Windows kernel driver Netwtw14.sys and assigned a verdict of Vulnerable with a composite risk score of 72/100, indicating a known or likely vulnerability surface (60-79 band).

VerdictVulnerable (72/100)
YARA matches0
Multi-engine detections0 / 76
File size5566368 bytes
Code-signing signerSectigo Public Code Signing Root R46
Analyzed2026-04-03
SHA256660ef8f59f3b2ff0454e27a8449ac7d3c00c983a04d44762acde717489d62121
SHA1ebb5dfcb2c571ba2b1ed33ae69ed756498514466
MD59c8198bb0504bb77a664829a47e477af

Driver identity

Version resource data embedded in the Netwtw14.sys PE header, as extracted by the analysis engine.

File descriptionR Intel Wireless WiFi Link Driver
ProductIntel® Wireless WiFi Link Adapter
CompanyIntel Corporation
Original filenameNetwtw14.sys
Internal nameNetwtw14.sys
File version23.50.12.1
CopyrightCopyright (C) 2025 Intel Corporation

How the 72/100 score breaks down

Each component is scored 0-100 and then weighted into the composite. See the analysis methodology for the exact formula.

ComponentSub-score
Multi-engine consensus0 / 100
YARA signature matches0 / 100
Dangerous kernel imports100 / 100
IOCTL dispatch surface100 / 100
Known-vulnerable corpus0 / 100
Code-signing state0 / 100
Packing and entropy0 / 100
Dynamic behaviour0 / 100
CVE cross-reference0 / 100

Kernel imports (19)

Kernel-mode APIs resolved from the Import Address Table of Netwtw14.sys, ranked by exploitation relevance.

APIRiskWhy it matters
MmMapLockedPagesSpecifyCachecriticalHighly dangerous - potential for arbitrary code execution, memory corruption, or process termination
MmGetSystemRoutineAddresshighPotentially dangerous - could be used for privilege escalation or security bypass
IoGetDeviceObjectPointermediumModerate risk - system modification capability
ZwQuerySystemInformationmediumModerate risk - system modification capability
KeBugCheckExmediumModerate risk - system modification capability
ZwWriteFilemediumModerate risk - system modification capability
ExAllocatePoolWithTaglowStandard kernel API - generally benign
KeInitializeEventlowStandard kernel API - generally benign
ZwQueryValueKeylowStandard kernel API - generally benign
ZwCloselowStandard kernel API - generally benign
DbgPrintExlowStandard kernel API - generally benign
RtlInitUnicodeStringlowStandard kernel API - generally benign
ZwReadFilelowStandard kernel API - generally benign
KeSetEventlowStandard kernel API - generally benign
ZwOpenFilelowStandard kernel API - generally benign
ZwOpenKeylowStandard kernel API - generally benign
ZwQueryInformationFilelowStandard kernel API - generally benign
KeWaitForSingleObjectlowStandard kernel API - generally benign
IoBuildDeviceIoControlRequestlowStandard kernel API - generally benign

IOCTL dispatch codes (40)

Control codes reachable through the driver dispatch routine. Codes tied to published exploit code are flagged, since they are the primary Bring Your Own Vulnerable Driver (BYOVD) entry points.

CodeSeverityTransferDescription
0x0022201Ccritical (known exploit)METHOD_BUFFEREDProcess termination by PID (wsftprm)
0x0080840FhighMETHOD_NEITHERFILE_DEVICE_CUSTOM Function #259
0xC350408BhighMETHOD_NEITHERCUSTOM_MSI Function #34
0x0080808BhighMETHOD_NEITHERFILE_DEVICE_CUSTOM Function #34
0x0080A88BhighMETHOD_NEITHERFILE_DEVICE_CUSTOM Function #2594
0x00808B8BhighMETHOD_NEITHERFILE_DEVICE_CUSTOM Function #738
0x0080878BhighMETHOD_NEITHERFILE_DEVICE_CUSTOM Function #482
0x0080868BhighMETHOD_NEITHERFILE_DEVICE_CUSTOM Function #418
0x00808F8BhighMETHOD_NEITHERFILE_DEVICE_CUSTOM Function #994
0x0034BAFFhighMETHOD_NEITHERFILE_DEVICE_DISK Function #3775
0x008086C7highMETHOD_NEITHERFILE_DEVICE_CUSTOM Function #433
0x0080B883highMETHOD_NEITHERFILE_DEVICE_CUSTOM Function #3616
0xC350418BhighMETHOD_NEITHERCUSTOM_MSI Function #98
0x0080B82BhighMETHOD_NEITHERFILE_DEVICE_CUSTOM Function #3594
0x0080E9FFhighMETHOD_NEITHERFILE_DEVICE_CUSTOM Function #2687
0x0080B08BhighMETHOD_NEITHERFILE_DEVICE_CUSTOM Function #3106
0x0080888BhighMETHOD_NEITHERFILE_DEVICE_CUSTOM Function #546
0x00809103highMETHOD_NEITHERFILE_DEVICE_CUSTOM Function #1088
0x0080818BhighMETHOD_NEITHERFILE_DEVICE_CUSTOM Function #98
0x00347B83highMETHOD_NEITHERFILE_DEVICE_DISK Function #3808
0x0080890FhighMETHOD_NEITHERFILE_DEVICE_CUSTOM Function #579
0x0080003FhighMETHOD_NEITHERFILE_DEVICE_CUSTOM Function #15
0x0080830FhighMETHOD_NEITHERFILE_DEVICE_CUSTOM Function #195
0x0080B88BhighMETHOD_NEITHERFILE_DEVICE_CUSTOM Function #3618

Showing 24 of 40 extracted control codes.

PE sections

Section layout and Shannon entropy. High entropy in a code section is a packing or encryption indicator.

SectionVirtual sizeRaw sizeEntropyFlags
.text0x3CBED70x3CC0006.36CODE, EXEC, READ
.rdata0x9DC780x9DE005.67IDATA, READ
.data0xC4D900x4D6001.91IDATA, READ, WRITE
.pdata0x2D8E80x2DA006.31IDATA, READ
PAGEcsrv0xA7820xA8006.23CODE, EXEC, READ
PAGE0x22C10x24005.96CODE, EXEC, READ
PAGEcsec0x000E0x02000.26CODE, EXEC, READ
PAGEcjaw0x0DC00x0E006.35CODE, EXEC, READ
PAGEcwfd0x120910x122006.4CODE, EXEC, READ
PAGEcimg0x253C0x26006.42CODE, EXEC, READ
PAGEccln0xEC590xEE006.24CODE, EXEC, READ
PAGEcsv_0x49E30x4A006.24CODE, EXEC, READ
PAGEcctw0x01410x02004.15CODE, EXEC, READ
PAGEdoid0x2E400x30003.12IDATA, READ, WRITE
PAGEdcln0x0EB00x10002.36IDATA, READ, WRITE
PAGEdSlr0x12980x14001.83IDATA, READ, WRITE
PAGEdMag0x12C00x14001.84IDATA, READ, WRITE
PAGEdBla0x12D00x14001.87IDATA, READ, WRITE
PAGEdHrp0x01400x02001.2IDATA, READ, WRITE
PAGEdGfp0x02580x04001.16IDATA, READ, WRITE
PAGEdMrp0x01E00x02001.72IDATA, READ, WRITE
PAGEdFmp0x02800x04001.24IDATA, READ, WRITE
PAGEdWhp0x02800x04001.24IDATA, READ, WRITE
PAGEdSim0x00480x02000.39IDATA, READ, WRITE
PAGEdFpg0x00780x02000.66IDATA, READ, WRITE
PAGEdSle0x00700x02000.63IDATA, READ, WRITE
PAGEdreg0xF54C0xF6002.39IDATA, READ, WRITE
PAGEdimg0x05D00x06005.07IDATA, READ, WRITE
PAGEdsv_0x00380x02000.2IDATA, READ, WRITE
PAGEdjaw0x00140x02000IDATA, READ, WRITE
INIT0x16520x18005.03CODE, EXEC, READ, DISCARD
.rsrc0xB8480xBA004.97IDATA, READ, DISCARD
.reloc0x85C00x86005.46IDATA, READ, DISCARD

Exploit mitigations

Control Flow GuardEnabled
ASLREnabled
DEPEnabled
Integrity checkEnforced
Mitigation score100 / 100

MITRE ATT&CK techniques (10)

Techniques this driver could enable if loaded by an adversary.

IDTechniqueTactic
T1003.001OS Credential Dumping: LSASS MemoryCredential Access
T1055.012Process HollowingDefense Evasion
T1068Exploitation for Privilege EscalationPrivilege Escalation
T1071Application Layer ProtocolCommand and Control
T1112Modify RegistryDefense Evasion
T1211Exploitation for Defense EvasionDefense Evasion
T1543.003Windows ServicePersistence
T1547.001Registry Run KeysPersistence
T1553.002Subvert Trust Controls: Code SigningDefense Evasion
T1652Device Driver DiscoveryDiscovery

Code-signing chain

SignerSectigo Public Code Signing Root R46
Signer organisationSectigo Limited
IssuerAAA Certificate Services
Serial48FC93B46055948D36A7C98A89D69416
Valid from2021-05-25 00:00 UTC
Valid until2028-12-31 23:59 UTC
Signature validityVerified

Symbolic execution

Engine angr, status completed, 100 paths explored at a maximum depth of 100. Vulnerability classes reached: 0. Exploitable paths: 0.

Frequently asked questions about Netwtw14.sys

Is Netwtw14.sys safe?

Based on DriverShield static and dynamic analysis, Netwtw14.sys is flagged as vulnerable and is a potential Bring Your Own Vulnerable Driver (BYOVD) risk. Its composite risk score is 72/100 (verdict: vulnerable). Always validate findings independently before acting.

What is the risk score of Netwtw14.sys?

Netwtw14.sys has a DriverShield composite risk score of 72/100, placing it in the vulnerable verdict band. SHA256: 660ef8f59f3b2ff0454e27a8449ac7d3c00c983a04d44762acde717489d62121.

What is Netwtw14.sys?

Netwtw14.sys is a Windows kernel-mode driver (.sys) analyzed by DriverShield for vulnerabilities, BYOVD abuse potential, and malware indicators. It is code-signed by Sectigo Public Code Signing Root R46.

Related: Other drivers signed by Sectigo Public Code Signing Root R46 · What an IOCTL dispatch code is · BYOVD research index · full driver database · CVE library · code signing atlas


DriverShield © 2025-2026 · Terms · Privacy · Contact