New Windows Driver Signature bypass allows kernel rootkit installs
ID: 29b89db8-de94-50b0-8df3-ed291294ec37
STIX ID: report--29b89db8-de94-50b0-8df3-ed291294ec37
Feed Name: Bleeping Computer
A researcher demonstrated a Windows 'downdate' technique that takes control of the Windows Update flow to install outdated kernel and VBS components (such as ci.dll), enabling bypass of Driver Signature Enforcement and disabling Virtualization-based Security protections. The method, shown on fully patched Windows 11 systems, allows loading unsigned kernel drivers and deploying rootkits, requires Administrator/kernel privileges, and has prompted Microsoft to develop mitigations while the update-takeover vector remains a concern.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
