Cyber Security News

New Windows Downgrade Attack Let Hackers Downgrade Patched Systems

Hackers often target Microsoft Windows primarily due to its widespread usage and market dominance. With more than 80% of the desktop OS market share, Windows system vulnerabilities present numerous exploitation opportunities.

SafeBreach analysts recently identified a new Windows Downgrade attack that enables hackers to downgrade and exploit the patched systems.

In August, security analyst (Alon Leviev) introduced “Windows Downdate” at “Black Hat USA 2024” and “DEF CON 32” that exposed critical Windows security vulnerabilities. 

The tool manipulates “Windows Update” to perform targeted downgrades of essential OS components that effectively revive previously patched vulnerabilities. 

While Microsoft addressed CVE-2024-21302 (a privilege escalation vulnerability affecting Windows virtualization), the core Windows Update compromise remains unpatched since Administrator-to-kernel code execution isn’t classified as a security boundary violation.

Protecting Your Networks & Endpoints With UnderDefense MDR – Request Free Demo

This research leveraged this to bypass “DSE,” allowing “unsigned kernel drivers” to load via the “ItsNotASecurityBoundary” exploit. 

This bypass works by exploiting “FFI” vulnerabilities and “TOCTOU” race conditions in security catalog validation.

Downgrading only ci.dll to its unpatched version (Source – Safe Breach)

Downgrade Attack

Specifically, by downgrading “ci.dll” to version 10.0.22621.1376 on “Windows 11 23h2 systems,” threat actors can evade “VBS” protections, even those enforced through “UEFI locks.” 

This allows the deployment of “rootkits” capable of hiding “malicious processes” and “network activity.” 

The attack succeeds by either modifying registry keys (for standard VBS configurations) or invalidating “SecureKernel.exe” (for UEFI-locked systems) which shows a critical flaw in the security architecture of the Windows that allows fully-patched systems to be compromised via controlled component downgrades.

Windows “VBS” implements a critical security feature that can be enhanced via two key mechanisms that are configurable via the “Windows Registry” or “Local Group Policy Editor”:- 

  • UEFI Lock
  • Mandatory flag
Configurations (Source – Safe Breach)

While UEFI Lock stores the VBS configuration in a specialized “UEFI NVBS” variable called “VbsPolicy” to prevent remote modifications this protection alone can be evaded via a sophisticated attack chain like “corrupting SecureKernel.exe” (a crucial VBS component), “downgrading the ci.dll” (Code Integrity module) to a vulnerable version, and “exploiting a security flaw” known as “ItsNotASecurityBoundary.”

To establish strong protection system administrators must enable both the “UEFI Lock” (using “reg add HKLM\SYSTEM\CurrentControlSet\Control\DeviceGuard /v Locked /t REG_DWORD /d 1 /f”) and the “Mandatory” flag (using “reg add HKLM\SYSTEM\CurrentControlSet\Control\DeviceGuard /v Mandatory /t REG_DWORD /d 1 /f”). 

These need to be followed by a system restart to prevent the kernel compromise via downgrade attacks. 

These are particularly dangerous as they can evade the “DSE” and exploit vulnerabilities in “first-party” components like “Windows kernel” itself without relying on the traditional “BYOVD” approach that makes it essential for security solutions to actively monitor and detect any attempted downgrade procedures.

Run private, Real-time Malware Analysis in both Windows & Linux VMs. Get a 14-day free trial with ANY.RUN!

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

2 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

3 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

4 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

4 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

4 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

6 hours ago