Microsoft Under Pressure to Bolster Defenses for BYOVD Attacks
ID: a2141e77-7d9a-526d-b6fd-1b74bda73d4b
STIX ID: report--a2141e77-7d9a-526d-b6fd-1b74bda73d4b
Feed Name: Dark Reading
Threat Score
This article examines the growing use of bring-your-own-vulnerable-driver (BYOVD) attacks—where threat actors drop and load signed but vulnerable kernel drivers to obtain ring-0 privileges and kill security products—highlighting real-world abuse (e.g., an EnCase driver weaponized, Black Basta/Reynolds campaigns), shortcomings in Windows driver-signing/backward-compatibility and Microsoft's blocklist cadence, and short- and medium-term mitigation strategies for vendors and defenders.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
