Security researcher Alon Leviev from SafeBreach demonstrated a method to bypass Windows security features by downgrading critical system components like Driver Signature Enforcement (DSE). This exploit could allow attackers to load unauthorized drivers, potentially deploying rootkits on even fully patched Windows systems. The technique involves manipulating the Windows Update process to install outdated, vulnerable software components, which the operating system then treats as fully patched.
โถCVSS Scores: The vulnerabilities exploited in this downgrade attack are ๐๐๐-๐๐๐๐-๐๐๐๐๐ (๐๐๐๐ ๐.๐) and ๐๐๐-๐๐๐๐-๐๐๐๐๐ (๐๐๐๐ ๐.๐). These scores reflect significant security impacts, given the risks associated with privilege escalation and system compromise.
โถ Research and Tool Release: Levievโs tool, ๐๐๐๐๐๐ค๐ ๐ท๐๐ค๐๐๐๐ก๐, enables attackers to create custom downgrade configurations, exposing up-to-date systems to vulnerabilities that have been previously patched, specifically targeting components like ๐๐ข.๐๐ฅ๐ฅ. This manipulation effectively undoes critical updates, exploiting weak spots in Windowsโ integrity checks and making the โfully patchedโ status misleading.
โถBypassing VBS: Virtualization-based Security (VBS), a core Windows security feature, can also be weakened through this downgrade attack. With modified registry keys and partial VBS configurations, attackers can downgrade essential files, like ๐๐ข.๐๐ฅ๐ฅ, bypassing the secure kernel integrity check. As well as replacing one of the VBS files, such as ๐๐๐๐ฎ๐ซ๐๐๐๐ซ๐ง๐๐ฅ.๐๐ฑ๐, with invalid files, preventing VBS from loading.
โถMicrosoftโs Response: Although Microsoft has acknowledged the risks associated with these downgrade tactics, it hasnโt classified the vulnerability as crossing a security boundary( because this exploit requires administrator privileges), meaning it is not yet fully patched. Microsoft states that it is working on a comprehensive fix, which will involve revoking certain unpatched files across affected systems, though a release date for this update is not yet confirmed.