Critical Windows Vulnerabilities Exposed, Patches in Development

20 Aug 2024

A proof-of-concept (PoC) exploit has emerged, demonstrating critical zero-day vulnerabilities in Microsoft Windows that facilitate a novel “downgrade attack.” These vulnerabilities, identified as CVE-2024-38202 and CVE-2024-21302, were initially unveiled by SafeBreach researcher Alon Leviev during the recent Black Hat USA 2024 and DEF CON 32 conferences.

Understanding the Vulnerabilities

The identified flaws allow an attacker to manipulate the Windows Update process, enabling a stealthy downgrade of a fully patched Windows system to an older, vulnerable version. This effectively reinvigorates previously resolved security issues, rendering them exploitable once more.

Leviev articulated the gravity of the situation, stating, “As a result, I was able to make a fully patched Windows machine susceptible to thousands of past vulnerabilities, turning fixed vulnerabilities into zero-days and making the term ‘fully patched’ meaningless on any Windows machine in the world.”

In a bid to raise awareness, Leviev has released the PoC exploit, named “Windows Downdate,” on GitHub. This tool automates the exploitation of the two zero-days, allowing for control over the Windows Update process and enabling the creation of “fully undetectable, invisible, persistent, and irreversible downgrades” on critical operating system components.

Technical Implications

Windows Downdate is capable of bypassing integrity verification, Trusted Installer enforcement, and various security checks, allowing it to downgrade essential Windows DLLs, drivers, and even the NT kernel. Additionally, it can downgrade components like Credential Guard and Hyper-V, re-exposing patched privilege escalation vulnerabilities.

The implications of this exploit are profound. An attacker could surreptitiously revert a fully up-to-date Windows deployment to a vulnerable state, thereby re-enabling exploitation of thousands of previously patched vulnerabilities. Notably, traditional scanning and recovery tools are ineffective against these malicious downgrades.

By exploiting unprotected elements of the Windows Update architecture, Windows Downdate can stealthily downgrade a fully patched system, while also disabling key security features in a manner that is challenging to detect and reverse.

Demo Source: Safebreach

Microsoft acknowledged these zero-days in advisories released on August 7, indicating that they are actively working on patches. However, with no fixes available a month later, Leviev felt compelled to publish the PoC to expedite awareness and encourage quicker remediation efforts.

In their advisory for CVE-2024-21302, Microsoft stated, “Microsoft is developing a security update that will revoke outdated, unpatched VBS system files to mitigate this vulnerability, but it is not yet available.” In the interim, Microsoft has suggested mitigation steps, such as implementing an Access Control List (ACL) or Discretionary Access Control List (DACL) to restrict access to the PoqexecCmdline registry key that facilitates the attack.

However, security experts caution that these measures are incomplete and can be easily circumvented by a determined attacker. The only comprehensive solution will be the installation of official security updates from Microsoft once they are released.

The Broader Context

This incident underscores the inherent dangers posed by zero-day vulnerabilities within core operating system components, which can be exploited to compromise systems and reintroduce previously patched vulnerabilities. It highlights the urgent need for more proactive research into these intricate attack surfaces.

Leviev emphasized the importance of vigilance, stating, “Design flaws in fundamental system processes like Windows Update can have far-reaching consequences. It’s crucial for both researchers and organizations to stay ahead of potential threats by continuously scrutinizing these critical components.”

Top charts for Desktop Windows

uTorrent

uTorrent

Latest update uTorrent download for free for Windows PC or Android mobile

5
1032 reviews
7508553
downloads
Zona

Zona

Latest update Zona download for free for Windows PC or Android mobile

4
614 reviews
1735311
downloads
WinRAR

WinRAR

Streamline file management with fast compression, secure your documents, and save space.

5
735 reviews
746713
downloads
Minecraft

Minecraft

Shape environments, explore vast worlds, and survive against monsters with endless creativity.

5
750 reviews
495630
downloads

News and reviews for Desktop Windows

Visio 2021 Professional Now $9.97 Until February 8

Microsoft offers Visio 2021 Professional for $9.97, down from $249, with added templates, until February 8.

Read more

Code Vein Offers Stylish Combat, Discounted Editions

Code Vein captivates with anime-style combat and offers discounted editions. Fast-paced action meets fun builds in this cult classic.

Read more

Microsoft Phases Out RC4 in Kerberos for Windows Security

Microsoft to eliminate RC4 in Kerberos by July 2026, enhancing Windows security.

Read more

Highguard Faces Criticism but Shows Potential for Growth

Highguard, launched with controversy, holds potential despite poor reviews. Offering genre innovation, it aims to evolve against negative feedback.

Read more

PS2Recomp Boosts Native PS2 Games with Recompilation

PS2Recomp, a new tool, promises enhanced native PS2 game ports, sparking interest among developers for PC platforms.

Read more

NVIDIA Introduces RTX Remix Logic for Classic Game Mods

NVIDIA's RTX Remix Logic, launched on 2026-01-27, enables dynamic modding of classic PC games with a no-code node-based interface.

Read more

Windows 11 Update KB5074109 Affects Legacy Modems

The Windows 11 update KB5074109 disrupts modems by removing several legacy drivers, causing connectivity issues for select users.

Read more

Anytype Replaces Notion, Obsidian, and Todoist for Unified Workflow

Anytype consolidates Notion, Obsidian, and Todoist functions, reducing context-switching and improving workflow efficiency.

Read more

ReBlade: Cyberpunk Roguelike Announced by ChillyRoom

ReBlade from ChillyRoom and Spiral Up Games announced for PC: cyberpunk roguelike offers high-speed action in a dystopian setting.

Read more

Artorias Battles Elden Ring Bosses in New Video Showcase

Artorias from Dark Souls faces Elden Ring bosses, demonstrating impressive skills in Fights' YouTube video.

Read more