Target Industry

Indiscriminate, opportunistic targeting.

Overview

This newly discovered vulnerability allows threat actors to downgrade fully patched Windows 11 systems to their unpatched and vulnerable versions. It can lead them to bypassing Windows security features, such as Driver Signature Enforcement (DSE), allowing the installation of rootkits and the hiding of malicious activities, and enable them to maintain persistence on compromised systems.

The vulnerability was demonstrated by Alon Leviev, a researcher at SafeBreach, at two security conferences. Leviev disclosed how this attack could be used to disable security software and install unsigned drivers.

Since Leviev reported this vulnerability to Microsoft, there have been patches released for the two vulnerabilities (CVE-2024-21302 and CVE-2024-38202). However, the ability for threat actors with admin access to exploit the Windows Update process to downgrade critical OS components remains unaddressed.

Impact

This new DSE bypass attack allows threat actors to load unsigned kernel drivers, enabling the installation of rootkits. These rootkits can disable security controls, hide malicious activities, and maintain persistent access to compromised systems, posing a significant threat to system security.

Exploitation

This attack utilises CVE-2024-21302 and CVE-2024-38202. Both vulnerabilities allow threat actors with administrative privileges to exploit the Windows Update process to downgrade system components to unpatched versions.

CVE-2024-38202 can lead to the installation of rootkits and other malicious software, bypassing security measures and compromising system integrity. Whereas CVE-2024-21302 can bypass Virtualisation-Based Security (VBS) features, leading to potential data exfiltration and system integrity compromises.

Containment, Mitigations & Remediations

If systems are severely compromised by this attack, it is recommended to perform a clean OS installation to eliminate any persistent threats. Additionally, using advanced endpoint protection solutions that can detect, and block rootkit activities is recommended.

Indicators of Compromise

Indicators of compromise for this attack could be:

  • Unexpected modifications to system files or configurations, particularly those related to Windows Update and kernel components
  • Presence of unsigned or suspicious drivers in the system
  • Unexpected disabling or interference with antivirus and other security tools.

Threat Landscape

The “Windows Downdate” attack highlights a significant threat landscape for fully patched Windows 11 systems. Threat actors can exploit the Windows Update process to revert critical OS components to their unpatched, vulnerable states. This vulnerability underscores the need for robust monitoring and advanced security measures to detect and mitigate such sophisticated attacks.

Threat Group

The specific threat group behind this vulnerability has not been publicly identified.

TTPs 

  • T1082 – System Information Discovery 
  • T1601 – Modify System Image 

Further Information 

 

Further Threat Intelligence from Quorum Cyber

Headquarters

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

FLORIDA, USA Office

501 E Kennedy Blvd.
STE 1400
Tampa FL 33602

Ontario, Canada Office

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

Contact Us
Address

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

501 E Kennedy Blvd
STE 1400
Tampa FL 33602

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

HEADQUARTERS
Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ



FLORIDA, USA OFFICE
501 E Kennedy Blvd.
STE 1400
Tampa FL 33602


ONTARIO, CANADA OFFICE
1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7


Legal

Privacy Preference Center

Skip to content