Security researcher Alon Levie of SafeBreach has discovered two vulnerabilities in Windows Update. Their exploitation allows you to downgrade the operating system to undo applied security patches in order to subsequently exploit known vulnerabilities for attacks. The issue affects Windows 11, Windows 10, and Windows Server.

Image source: Copilot

Using these vulnerabilities, an attacker can remove previously downloaded security updates from a Windows device in order to be able to exploit old vulnerabilities that have already been patched. In fact, an attacker can “roll back” the updated OS to an older version, in which already fixed vulnerabilities remain relevant.

This news is unpleasant for Windows users who regularly update their OS and install the latest security patches. According to the source, Microsoft has been aware of the mentioned problem since February 2024, but so far the software giant has not released fixes for these vulnerabilities. Microsoft is known to be working on a fix and has also released some details about CVE-2024-38202 and CVE-2024-21302 that will help limit potential damage while there is no official patch yet.

Ultimately, the vulnerabilities mentioned could give an attacker complete control over the update process to downgrade critical Windows components such as dynamic link libraries (DLLs) and the NT kernel. The researcher also discovered that the entire virtualization stack was at risk. He managed to downgrade the Hyper-V hypervisor, Secure Kernel and Credential Guard. All this makes it possible to use previously closed vulnerabilities to compromise the system. At the same time, when checking through Windows Update, the system itself looks as if it is still updated to the current version.

According to Microsoft, there is currently no evidence that Windows Update vulnerabilities were used in actual hacking attacks. It is not yet known when exactly a patch will be released to fix the problem.

admin

Share
Published by
admin

Recent Posts

OpenAI accidentally deleted potential evidence in copyright lawsuit

Late last year, a lawsuit began in which The New York Times and other major…

10 minutes ago

Hidden features of Microsoft Bing Wallpaper scared users

Microsoft has released the Bing Wallpaper app, which updates your desktop background daily using images…

39 minutes ago

“There will be more to come”: a Rockstar employee intrigued fans with “absolutely mind-blowing things” in GTA VI

While fans eagerly await the next GTA VI trailer, Rockstar Games' ambitious open-world crime thriller…

50 minutes ago

“James Webb” was the first in history to find the “Einstein zigzag” – a unique curvature of space-time

Gravitational lensing, predicted 90 years ago by Einstein, was confirmed by observation four years after…

1 hour ago

The second Xiaomi electric car will be released a year after the first and will be noticeably different from it

Xiaomi's efforts to carve out its place in China's highly competitive electric vehicle market are…

2 hours ago