logo

New Windows Driver Signature bypass allows kernel rootkit installs

ID: 29b89db8-de94-50b0-8df3-ed291294ec37

STIX ID: report--29b89db8-de94-50b0-8df3-ed291294ec37

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2024-10-26

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

A researcher demonstrated a Windows 'downdate' technique that takes control of the Windows Update flow to install outdated kernel and VBS components (such as ci.dll), enabling bypass of Driver Signature Enforcement and disabling Virtualization-based Security protections. The method, shown on fully patched Windows 11 systems, allows loading unsigned kernel drivers and deploying rootkits, requires Administrator/kernel privileges, and has prompted Microsoft to develop mitigations while the update-takeover vector remains a concern.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.