Target Industry
Indiscriminate, opportunistic targeting.
Overview
This newly discovered vulnerability allows threat actors to downgrade fully patched Windows 11 systems to their unpatched and vulnerable versions. It can lead them to bypassing Windows security features, such as Driver Signature Enforcement (DSE), allowing the installation of rootkits and the hiding of malicious activities, and enable them to maintain persistence on compromised systems.
The vulnerability was demonstrated by Alon Leviev, a researcher at SafeBreach, at two security conferences. Leviev disclosed how this attack could be used to disable security software and install unsigned drivers.
Since Leviev reported this vulnerability to Microsoft, there have been patches released for the two vulnerabilities (CVE-2024-21302 and CVE-2024-38202). However, the ability for threat actors with admin access to exploit the Windows Update process to downgrade critical OS components remains unaddressed.
Impact
This new DSE bypass attack allows threat actors to load unsigned kernel drivers, enabling the installation of rootkits. These rootkits can disable security controls, hide malicious activities, and maintain persistent access to compromised systems, posing a significant threat to system security.
Exploitation
This attack utilises CVE-2024-21302 and CVE-2024-38202. Both vulnerabilities allow threat actors with administrative privileges to exploit the Windows Update process to downgrade system components to unpatched versions.
CVE-2024-38202 can lead to the installation of rootkits and other malicious software, bypassing security measures and compromising system integrity. Whereas CVE-2024-21302 can bypass Virtualisation-Based Security (VBS) features, leading to potential data exfiltration and system integrity compromises.
Containment, Mitigations & Remediations
If systems are severely compromised by this attack, it is recommended to perform a clean OS installation to eliminate any persistent threats. Additionally, using advanced endpoint protection solutions that can detect, and block rootkit activities is recommended.
Indicators of Compromise
Indicators of compromise for this attack could be:
- Unexpected modifications to system files or configurations, particularly those related to Windows Update and kernel components
- Presence of unsigned or suspicious drivers in the system
- Unexpected disabling or interference with antivirus and other security tools.
Threat Landscape
The “Windows Downdate” attack highlights a significant threat landscape for fully patched Windows 11 systems. Threat actors can exploit the Windows Update process to revert critical OS components to their unpatched, vulnerable states. This vulnerability underscores the need for robust monitoring and advanced security measures to detect and mitigate such sophisticated attacks.
Threat Group
The specific threat group behind this vulnerability has not been publicly identified.
TTPs
- TA0003 – Persistence
- T1014 – Rootkit
- T1082 – System Information Discovery
- T1562.010 – Downgrade Attack
- T1601 – Modify System Image
Further Information












