accellid.sys
ECS laptop lid-accelerometer driver
AccelLid.sys is a signed kernel driver from Elitegroup Computer Systems (ECS), a Taiwanese OEM that builds motherboards and laptops. Its OriginalFilename identifies it as a "Lid Accelerometer Driver": the low-level component that reads a laptop's lid and motion sensor. If it is on your machine, the ordinary explanation is that you have an ECS-built laptop and its bundled system software.
It is on the public LOLDrivers list following a September 2024 disclosure by Northwave Cyber Security, scored CVSSv3 5.5 (a local denial-of-service). The driver exposes IOCTL paths for accelerometer commands, keyboard control, event registration, and ACPI method execution, which is more low-level surface than a lid sensor needs to hand to any local caller. No CVE has been assigned, but the finding is documented and named.
Microsoft's Vulnerable Driver Blocklist denies this driver across all file versions for the matching Elitegroup publisher and signing roots, so on a current Windows 11 install with the blocklist enabled the older binary should be blocked from loading.
If the driver is on an ECS laptop, that is expected; check ECS's support page for your model and update the bundled system software. If nothing you installed accounts for it, the blocklist is the backstop.
accellid.sys is listed as a known-vulnerable driver on the public LOLDrivers project. One distinct binary hash matching this filename is on record.
Status data comes from the public LOLDrivers project, a community-curated registry of drivers known to be vulnerable or malicious. The snapshot Vera uses was refreshed July 20, 2026. CVE links go to the NIST National Vulnerability Database.
Vera Project. “accellid.sys.” Vera Field Guide (Driver). The Vera Project. https://www.veraproject.xyz/field-guide/drivers/accellid-sys
