@r000t@infosec.exchange Wait, I do not understand that. If a driver is signed by Microsoft, then EVEN NON-ADMIN USERS can load them?

That... sucks. But it explains finally to me why that github project that contains a huge .h file with the driver is a real PoC :)