pwshub.com

Researchers disclose Windows "downgrade" attack as Microsoft provides a mitigation method

Serving tech enthusiasts for over 25 years.
TechSpot means tech analysis and advice you can trust.

In a nutshell: Researchers have developed a cyberattack that reverses Windows security updates to exploit previously patched vulnerabilities. Although they cannot deploy the malware remotely, users should observe standard security practices, even on fully updated operating systems. Microsoft has released a detailed guide for minimizing the risk of a downgrade attack as the company develops a more comprehensive solution.

Security researchers from SafeBreach labs have published the code for software that can roll back Windows to reopen old security vulnerabilities. Microsoft hasn't fully addressed the issue yet, but instituting a strict revocation policy can help defend against it until a proper fix is available.

Attackers can use the exploit, which the researchers dubbed Downdate, to revert Windows to an outdated version and then assume complete control over a system using previously patched flaws. Downdate can sidestep security measures like virtualization-based security (VBS), Windows Defender, UEFI locks, and Credential Guard. Windows 10, 11, and Server versions 2019 and later are affected.

SafeBreach released the Downdate software on GitHub to facilitate further research of the issue. The current version can only be used by the person physically operating the PC, but hackers could theoretically integrate it into malware payloads.

Microsoft lists the threat under two CVEs – 2024-21302 and 2024-38202. It started working on a solution when SafeBreach alerted it to the vulnerability in February. However, the company said that the process is slow because Downdate affects numerous aspects of Windows, and a solution will require extensive testing.

In the meantime, developers have a mitigation method that can provide an extra layer of security. The Windows support website includes instructions for revoking outdated VBS system files, which causes the UEFI firmware to institute additional checks during startup. However, the procedure risks making a system unbootable if users aren't careful. Microsoft advises users and admins not to use it on earlier versions of Windows, and all boot devices must first install updates released after August 13, 2024. The rule also applies to external boot media and the Windows Recovery Environment.

Although Downdate affects fully updated versions of Windows, users should always remain up-to-date with security patches and install Microsoft's remedy for the vulnerability when it releases. The company also suggests that users remain cautious when checking email and only install software from trusted sources.

Source: techspot.com

Related stories
1 month ago - A significant vulnerability in Microsoft Windows security tools was unveiled at the Black Hat security conference. Alon Leviev, a researcher from SafeBreach, showcased a method to exploit the Windows update process, enabling attackers to...
3 weeks ago - Researchers find it's possible to downgrade authentication checks, and shabby token refresh policies Digital wallets like Apple Pay, Google Pay, and PayPal can be used to conduct transactions using stolen and cancelled payment cards,...
2 weeks ago - There's a new method hackers are using to exploit Windows devices, which can expose numerous old vulnerabilities to allow them to take full control of your system.
1 month ago - The company says it is working on fixes for flaw presented at annual Black Hat security conference.
1 week ago - Google today announced that it's releasing Android 15 in the coming weeks. It also pushed the Android 15 source code to the Android Open Source...
Other stories
52 seconds ago - We tested multiple types of adjustable dumbbells, and these are the ones that made the cut.
1 minute ago - More states are offering the ability to change your Medigap coverage to purchase a cheaper plan without a physical exam.
1 minute ago - Why You Can Trust CNET Our expert, award-winning staff selects the products we cover and rigorously researches and tests our top picks. If you buy...
1 minute ago - Revised App Review Guidelines are now being applied to iPadOS 18, the latest version of its iPad-exclusive operating system. The OS will give European users the ability to access apps from third-party sources beyond the traditional App...
1 minute ago - Doom's Henchmen face off against Allies of the Avengers in the new game mode that'll arrive in Fortnite on Sept. 17.