logo

Windows 'Downdate' Attack Reverts Patched PCs to a Vulnerable State

ID: 04ff7112-d58f-5c8a-b69d-a943226b9952

STIX ID: report--04ff7112-d58f-5c8a-b69d-a943226b9952

Feed Name: Dark Reading

Threat Score
70/100

Date Published: 2024-10-28

Date Updated: 2026-04-21

Author: Jai Vijayan, Contributing Writer

...
...

**Windows Downdate / downgrade attacks** — A SafeBreach researcher demonstrated that an attacker with admin privileges can tamper with the Windows Update process to downgrade patched OS components (for example ci.dll) on fully patched Windows 11 systems, revive DSE bypasses, load unsigned kernel drivers, and deploy rootkits; some CVEs exploited in the chain (CVE-2024-21302 and CVE-2024-38202) were patched, but the fundamental ability to downgrade system files remains unmitigated and Microsoft is developing mitigations (including revoking outdated VBS files and recommending VBS with UEFI lock and 'Mandatory' flag) to reduce the risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.