Windows Downgrade Disaster: Critical Flaws Turn Fully Patched Systems into Vulnerability Time Bombs

Microsoft is developing security updates to tackle two vulnerabilities in the Windows update architecture that could lead to downgrade attacks. These flaws, discovered by Alon Leviev of SafeBreach Labs, could make a fully patched Windows system susceptible to past vulnerabilities, turning “fully patched” into a…

Hot Take:

Microsoft is essentially playing a high-stakes game of Jenga with its Windows update system, and two bricks just got pulled out. Get ready for a potential crash, unless those updates come faster than a Windows 10 reboot!

Key Points:

  • Two new security vulnerabilities in Windows update architecture: CVE-2024-38202 (CVSS score: 7.3) and CVE-2024-21302 (CVSS score: 6.7).
  • Discovered by SafeBreach Labs researcher Alon Leviev and presented at Black Hat USA 2024 and DEF CON 32.
  • Potential for attackers to perform downgrade attacks, reintroducing old vulnerabilities and bypassing security features.
  • Tool named “Windows Downdate” demonstrated to exploit these vulnerabilities.
  • Microsoft working on security updates to address these issues.

Membership Required

 You must be a member to access this content.

View Membership Levels
Already a member? Log in here