Type above and press Enter to search. Press Esc to cancel.

Loading...
Close Menu
  • Biology
  • Chemistry
  • Earth
  • Health
  • Physics
  • Science
  • Space
  • Technology
Facebook X (Twitter) Instagram

Quantumis

  • Biology
  • Chemistry
  • Earth
  • Health
  • Physics
  • Science
  • Space
  • Technology
Facebook X (Twitter) Pinterest YouTube
Quantumis
Home » » Security researcher discovered attack to downgrade Windows permanently

Security researcher discovered attack to downgrade Windows permanently

Facebook Twitter Pinterest Telegram LinkedIn WhatsApp Email Reddit
Share
Facebook Twitter LinkedIn Pinterest Telegram Email Reddit

One of the most important advices when it comes to the security of electronic devices is to make sure that they are up to date.

A security researcher discovered a new attack that downgrades Windows devices permanently. Information on the attack are available on the SafeBreach website.

Microsoft releases monthly security updates for Windows. It may also release out-of-bounds security updates; these are released when new vulnerabilities are actively exploited.

Good to known: Downgrading refers to uninstalling certain updates from a device. This may refer to uninstalling newer feature updates, but also to uninstalling a newer version of Windows.

While it is sometimes necessary to downgrade a PC, for instance when a new version is causing issues that cannot be fixed at the time, the process may also be used to remove certain security updates or protections from the operating system.

The Windows Downgrade Attack

Security researcher Alon Leviev developed the tool Windows Downdate to demonstrate that downgrade attacks are possible, even on fully patched versions of Windows.

He describes the tool in the following way: "a tool to take over the Windows Update process to craft fully undetectable, invisible, persistent, and irreversible downgrades on critical OS components—that allowed me to elevate privileges and bypass security features".

With the help of the tool, Leviev was able to turn fully patched and secured Windows devices to outdated Windows devices that were "susceptible to thousands of past vulnerabilities".

Leviev unveiled the research project at Black Hat USA 2024 and Def Con 32.  He managed to downgrade a fully patched Windows system successfully during demonstrations and prepared the systems in a special way, so that Windows Update would not find new updates.

To make matters worse, the downgrade attack is both undetectable by endpoint detection and response solutions and invisible in regards to the operating system's components. In other words, the operating system appears up-to-date, when in fact it is not.

The downgrade is also persistent and irreversible. The latter means that scan and repair tools to not detect issues or may repair the downgrade.

You may check out the blog post on the SafeBreach website for technical details.

Microsoft's response

Microsoft was informed about the vulnerability in advance. It is tracking the issues here:

  • CVE-2024-21302 -- Windows Secure Kernel Mode Elevation of Privilege Vulnerability
  • CVE-2024-38202 -- Windows Update Stack Elevation of Privilege Vulnerability

The maximum severity of both issues was set to important by Microsoft.

Microsoft has already added a detection to Microsoft Defender for Endpoint. This is designed to alert customers of exploit attempts.

The company is recommending several actions next to this. While they do not "mitigate the vulnerability", they "reduce the risk of exploitation".

In a nutshell:

  • Configure “Audit Object Access” settings to monitor attempts to access files, such as handle creation, read / write operations, or modifications to security descriptors.
  • KAuditing sensitive privileges used to identify access, modification, or replacement of VBS related files could help indicacte attempts to exploit this vulnerability.
  • Protect your Azure tenant by investigating administrators and users flagged for risky sign-ins and rotating their credentials.
  • Enabling Multi-Factor Authentication can also help alleviate concerns about compromised accounts or exposure.

Closing Words

The attack does require administrative privileges. A good precaution is to use a regular user account for day-to-day activities on Windows PCs. Microsoft will release a fix for the issue in the future.

What is your take on this? Feel free to leave a comment down below.

Share. Facebook Twitter Pinterest LinkedIn Email Reddit

Related Articles

Here is another reason why you should never click on ads to download software

Your next PC may come with the Google Essentials app - what you need to know

Here are the best features in macOS Sequoia 15

Windows Recall: Microsoft's second launch attempt after devastating criticism

Google Chrome: removal of uBlock Origin and other unsupported extensions has started

Google appears to be working on a better alias system for Gmail

Apple patches 2 zero-day vulnerabilities that were used to attack Intel-based Macs

Hackers claim to have cracked Microsoft's software licensing protection almost entirely

AdGuard Mail: email alias and temp email service from the makers of the adblocker

Cybersecurity Alert: Users Deceived By Fake Google CAPTCHA Pages

Comment

Leave A Reply Cancel Reply

Trending News

Beyond Deletion: How Stellar File Eraser Handles Folder Wiping and Free Space Erasure on Multiple Platforms

iOS 18 has been released, here are the best new features in it

How to fix RustDesk not working on macOS

Apple patches 2 zero-day vulnerabilities that were used to attack Intel-based Macs

Brave Search introduces AI follow-up questions - here is how it works

Firefox-maker Mozilla's boosted revenue significantly in 2023, but the financial report may also raise concern

ChatGPT Search is now available for free users

VLC to add support for offline AI subtitles and translations

Netflix prices are increasing again

North America Faced Majority of Ransomware Incidents in December 2024

Follow Quantumis
  • Facebook
  • Twitter
  • YouTube
  • Pinterest
SciTech News
  • Biology News
  • Chemistry News
  • Earth News
  • Health News
  • Physics News
  • Science News
  • Space News
  • Technology News
Recent Posts
  • Proton VPN: free VPN users can use the browser extensions now
  • Microsoft’s controversial Windows Recall feature is coming back in October
  • Windows 10 Start Menu will soon display ads for Microsoft 365
  • You need a final BIOS update to fix the Intel CPU stability issue for good
  • Firefox-maker Mozilla's boosted revenue significantly in 2023, but the financial report may also raise concern
  • How to rebuild the icon cache in Windows 11
Copyright © 2025 Quantumis. All Rights Reserved.
  • About
  • Contact
  • Privacy Policy
  • Terms of Use