Windows 11 and Server 2025 Update to Block Untrusted Cross-Signed Kernel Drivers by Default
ID: ba5ca6ee-2946-5761-bf82-33f5e9c0c8e0
STIX ID: report--ba5ca6ee-2946-5761-bf82-33f5e9c0c8e0
Feed Name: cybersecurityNews.com
Microsoft will block drivers signed via the deprecated cross-signed root program by default starting with the April 2026 update for Windows 11 and Windows Server 2025, requiring drivers to be certified through the Windows Hardware Compatibility Program. The change closes a legacy signing trust that enabled credential theft and rootkits, introduces an allowlist and careful audit/enforcement rollout to avoid disruption, and provides enterprise options to trust internally signed kernel drivers via Application Control tied to UEFI Secure Boot.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
