---
title: "Commonly Abused Windows Token Privileges: SeLoadDriverPrivilege"
description: SeLoadDriverPrivilege — Load and unload device drivers Determines which users can dynamically load and unload device drivers. This user right is not required if a signed driver for the new…
---

[Senteon Blog ](https://senteon.co/blog)

# [Commonly Abused Windows Token Privileges: SeLoadDriverPrivilege](https://senteon.co/blog/2021/10/commonly-abused-windows-token-privileges-seloaddriverprivilege)

 Written by [Henry Zhang](https://senteon.co/blog/author/henry-zhang) | Oct 17, 2021 2:00:00 PM

#### SeLoadDriverPrivilege — Load and unload device drivers

Determines which users can dynamically load and unload device drivers. This user right is not required if a signed driver for the new hardware already exists in the driver.cab file on the device. Device drivers run as highly privileged code. Windows supports the Plug and Play specifications that define how a computer can detect and configure newly added hardware, and then automatically install the device driver. Prior to Plug and Play, users needed to manually configure devices before attaching them to the device. This model allows a user to plug in the hardware, then Windows searches for an appropriate device driver package and automatically configures it to work without interfering with other devices.

Because device driver software runs as if it is a part of the operating system with unrestricted access to the entire computer, it is critical that only known and authorized device drivers be permitted.

##### GPO Setting Path

Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment

##### GPO Setting Name

Load and unload device drivers

##### Token Privilege

SeLoadDriverPrivilege

##### Associated ATT&CK Tactic(s)

Persistence (TA0003), Privilege Escalation (TA0004), Defense Evasion (TA0005)

[View full post](https://senteon.co/blog/2021/10/commonly-abused-windows-token-privileges-seloaddriverprivilege)

```json
{
  "@context" : "http://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Henry Zhang"
  },
  "dateModified" : "2025-11-04T18:08:23.124Z",
  "datePublished" : "2021-10-17T14:00:00Z",
  "headline" : "Commonly Abused Windows Token Privileges: SeLoadDriverPrivilege",
  "image" : {
    "@type" : "ImageObject",
    "height" : 60,
    "url" : "/hs/hsstatic/content_shared_assets/static-1.4092/img/default-amp-logo.png",
    "width" : 60
  },
  "mainEntityOfPage" : "https://senteon.co/blog/2021/10/commonly-abused-windows-token-privileges-seloaddriverprivilege",
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "height" : 60,
      "url" : "/hs/hsstatic/content_shared_assets/static-1.4092/img/default-amp-logo.png",
      "width" : 60
    },
    "name" : "Senteon Blog"
  }
}
```