Skip to main content

There’s a scary new way to undo Windows security patches

Person sitting and using an HP computer with Windows 11.
Microsoft

Security patches for Windows are essential for keeping your PC safe from developing threats. But downgrade attacks are a way of sidestepping Microsoft’s patches, and a security researcher set out to show just how fatal these can be.

SafeBreach security researcher Alon Leviev mentioned in a company blog post that they’d created something called the Windows Downdate tool as a proof-of concept. The tool crafts persistent and irreversible downgrades on Windows Server systems and Windows 10 and 11 components.

Recommended Videos

Leviev explains that his tool (and similar threats) performs a version-rollback attack, “designed to revert an immune, fully up-to-date software back to an older version. They allow malicious actors to expose and exploit previously fixed/patched vulnerabilities to compromise systems and gain unauthorized access.”

He also mentions that you can use the tool to expose the PC to older vulnerabilities sourced in drivers, DLLs, Secure Kernel, NT Kernel, the Hypervisor, and more. Leviev went on to post the following on X (formerly Twitter): “Other than custom downgrades, Windows Downdate provides easy to use usage examples of reverting patches for CVE-2021-27090, CVE-2022-34709, CVE-2023-21768 and PPLFault, as well as examples for downgrading the hypervisor, the kernel, and bypassing VBS’s UEFI locks.”

If you have not checked it out yet, Windows Downdate tool is live! You can use it to take over Windows Updates to downgrade and expose past vulnerabilities sourced in DLLs, drivers, the NT kernel, the Secure Kernel, the Hypervisor, IUM trustlets and more!https://t.co/59DRIvq6PZ

— Alon Leviev (@_0xDeku) August 25, 2024

What’s also concerning is that the tool is undetectable because it can’t be blocked by endpoint detection and response (EDR) solutions, and your Windows computer will continue to tell you it’s up to date even though it’s not. He also uncovered various ways to turn off Windows virtualization-based security (VBS), including Hypervisor-Protected Code integrity (HVCI) and Credential Guard.

Microsoft released a security update (KB5041773) on August 7 to fix the CVE-2024-21302 Windows Secure Kernel Mode privilege escalation flaw and a patch for CVE-2024-38202. Microsoft has also released some tips Windows users can take to stay safe, such as configuring “Audit Object Access” settings to scan for file access attempts. The release of this new tool shows how exposed PCs are to all sorts of attacks and how you should never let your guard down when it comes to cybersecurity.

The good news is that we can rest easy for now since the tool was created as a proof-of-concept, an example of “white-hat hacking” to discover vulnerabilities before threat actors do. Also, Leviev handed over his findings to Microsoft in February 2024, and hopefully, the software giant will have the necessary fixes soon.

Judy Sanhz
Judy Sanhz is a Digital Trends computing writer covering all computing news. Loves all operating systems and devices.
Microsoft is making a major change to using your iPhone in Windows
The Dell XPS 13 on a table with the Start Menu open.

In a recent Windows Insider Blog post, Microsoft announced it's adding the option for iPhone users to access their phones from the Start menu. Thanks to a special widget next to the Start menu, when you connect your phone, you can see data such as notifications, battery indicators, recent contacts, connection status, and more.

To enjoy this feature, you must use the recent Windows 11 preview build from the Dev and Beta channels, and you must be a Windows Insider. You must also update the Phone Link app to version 1.24121.30.0 or higher, have a Microsoft account, and have a PC that supports Bluetooth LE. Microsoft said it does not support PCs running Pro Education or Education SKUs. Even if this doesn't affect you, the update is rolling out in phases, so reaching your PC might take some time if you don't already have it.

Read more
Microsoft confirms audio bug hitting multiple versions of Windows
Ifi Go Bar DAC/amp dongle for headphones.

Microsoft has confirmed that a recent bug that has been affecting several Windows OS versions will be addressed with a fix; however, users can tackle the issue with a manual stopgap.

The bug is affecting the audio systems of Windows 11 and Windows 10 versions that have installed the January 2025 security update, rendering sounds on PCs non-functional. The malfunction is especially likely to happen if you have an audio DAC (digital-to-analog converter) connected to your computer via USB.

Read more
Microsoft just added a secret file sharing feature to Windows 11
Drag Tray feature on Windows Insiders build.

Another secret feature has been spotted in one of the latest Windows 11 Insider preview builds. Discovered by X user phantomofearth and reported by Tom's Hardware, it appears that Microsoft is trying out a 'Drag Tray' for sharing files. When you pick up a file and drag it toward the top of the screen, a tray will drop down with different sharing options.

The feature was found in Build 22635.4805 but it's not included in Microsoft's release notes, which means there's no saying if or when it will make it to the general release of Windows 11. Anything that makes sharing files easier is a welcome feature, however, so fingers crossed that Microsoft gets it working well and decides to push it to everyone.

Read more