Close Menu
Indo Guard OnlineIndo Guard Online
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
What's Hot

CISCO’s critical vulnerability in uniform grants on root access to static credentials

July 3, 2025

North Korean Hackers Target Web3 with malicious NIM software and use Clickfix in Babyshark

July 2, 2025

Hackers using PDFs to get yourself for Microsoft, Docusign and more in phishing campaigns return call

July 2, 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram YouTube
Indo Guard OnlineIndo Guard Online
Subscribe
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
Indo Guard OnlineIndo Guard Online
Home » A Windows downgrade attack threatens to expose patched systems to old vulnerabilities
Global Security

A Windows downgrade attack threatens to expose patched systems to old vulnerabilities

AdminBy AdminAugust 8, 2024No Comments3 Mins Read
Windows Downgrade Attack
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link


August 8, 2024Ravi LakshmananWindows Security/Vulnerabilities

Windows Downgrade attack

Microsoft said it is developing security updates to address two vulnerabilities it says could be used to launch attacks to downgrade the Windows Update architecture and replace current versions of Windows files with older versions.

The vulnerabilities are listed below –

  • CVE-2024-38202 (CVSS Score: 7.3) – Windows Update Stack Elevation of Privilege Vulnerability
  • CVE-2024-21302 (CVSS Score: 6.7) – Elevation of privilege vulnerability in Windows Secure Kernel Mode

The detection and reporting of flaws belongs to SafeBreach Labs researcher Alon Leviev, who presented the findings on Black Hat USA 2024 and DEF CON 32.

Cyber ​​security

CVE-2024-38202, which is implemented in the Windows Backup component, allows “an attacker with basic user privileges to reintroduce previously mitigated vulnerabilities or bypass certain virtualization-based security (VBS) features,” the tech giant said.

However, it was noted that an attacker attempting to exploit the flaw would need to convince an administrator or user with delegated permissions to perform a system restore that inadvertently causes the vulnerability.

The second vulnerability also addresses the case of elevation of privilege on Windows systems that support VBS, effectively allowing an adversary to replace current versions of Windows system files with outdated versions.

The implications of CVE-2024-21302 are that it can be weaponized to reintroduce previously resolved security flaws, bypass certain VBS features, and leak VBS-protected data.

Windows Downgrade attack

Leviev, who detailed a tool called Windows Downdate, said this can be used to make “a fully patched Windows machine susceptible to thousands of past vulnerabilities, turning patched vulnerabilities into zero days and rendering the term ‘fully patched’ meaningless on any Windows machine in the world.”

The tool, Leviev added, can “take over the Windows Update process to create completely invisible, invisible, permanent and irreversible downgrades of critical OS components — this allowed me to elevate privileges and bypass security features.”

In addition, Windows Downdate is able to bypass verification steps such as integrity checks and the use of a trusted installer, which actually allows you to downgrade critical operating system components, including dynamic link libraries (DLLs), drivers, and the NT kernel.

Cyber ​​security

On top of that, these issues can be used to downgrade the Credential Guard isolated user mode process, the secure kernel, and the Hyper-V hypervisor to expose past privilege escalation vulnerabilities, as well as disable VBS along with features like hypervisor-protected code integrity ( HVCI).

The end result is that a fully patched Windows system can become susceptible to thousands of past vulnerabilities and turn patched flaws into zero days.

These downgrades have the added effect of telling the operating system that the system is fully up-to-date, while preventing future updates from being installed and preventing detection by recovery and scanning tools.

“The downgrade attack I was able to perform on the Windows virtualization stack was possible due to a design flaw that allowed less privileged virtual layers/rings of trust to update components that reside in more privileged virtual layers/rings of trust,” Leviev said.

“This was very surprising given that the Microsoft VBS features were announced in 2015, which means that the downgrade attack surface I discovered has been around for almost a decade.”

Did you find this article interesting? Follow us Twitter  and LinkedIn to read more exclusive content we publish.





Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Admin
  • Website

Related Posts

CISCO’s critical vulnerability in uniform grants on root access to static credentials

July 3, 2025

North Korean Hackers Target Web3 with malicious NIM software and use Clickfix in Babyshark

July 2, 2025

Hackers using PDFs to get yourself for Microsoft, Docusign and more in phishing campaigns return call

July 2, 2025

This network traffic looks legal but it can hide a serious threat

July 2, 2025

US Sanctions of Russia

July 2, 2025

V0 AI Vercel tool, armed with cybercrime for quick creation pages to enter scale

July 2, 2025
Add A Comment
Leave A Reply Cancel Reply

Loading poll ...
Coming Soon
Do You Like Our Website
: {{ tsp_total }}

Subscribe to Updates

Get the latest security news from Indoguardonline.com

Latest Posts

CISCO’s critical vulnerability in uniform grants on root access to static credentials

July 3, 2025

North Korean Hackers Target Web3 with malicious NIM software and use Clickfix in Babyshark

July 2, 2025

Hackers using PDFs to get yourself for Microsoft, Docusign and more in phishing campaigns return call

July 2, 2025

This network traffic looks legal but it can hide a serious threat

July 2, 2025

US Sanctions of Russia

July 2, 2025

V0 AI Vercel tool, armed with cybercrime for quick creation pages to enter scale

July 2, 2025

Critical vulnerability in Anthropic MCP exposes machines for remote feats

July 1, 2025

Ta829 and Unk_greensec share tactics and infrastructure in current malware

July 1, 2025
About Us
About Us

Provide a constantly updating feed of the latest security news and developments specific to Indonesia.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

CISCO’s critical vulnerability in uniform grants on root access to static credentials

July 3, 2025

North Korean Hackers Target Web3 with malicious NIM software and use Clickfix in Babyshark

July 2, 2025

Hackers using PDFs to get yourself for Microsoft, Docusign and more in phishing campaigns return call

July 2, 2025
Most Popular

In Indonesia, crippling immigration ransomware breach sparks privacy crisis

July 6, 2024

Why Indonesia’s Data Breach Crisis Calls for Better Security

July 6, 2024

Indonesia’s plan to integrate 27,000 govt apps in one platform welcomed but data security concerns linger

July 6, 2024
© 2025 indoguardonline.com
  • Home
  • About us
  • Contact us
  • Privacy Policy

Type above and press Enter to search. Press Esc to cancel.