logo

Windows Update downgrade attack "unpatches" fully-updated systems

ID: f9e11fbb-5ea6-5031-9069-ff3c007a831e

STIX ID: report--f9e11fbb-5ea6-5031-9069-ff3c007a831e

Feed Name: Bleeping Computer

Threat Score
80/100

Date Published: 2024-08-07

Date Updated: 2026-07-18

Author: Sergiu Gatlan

...
...

SafeBreach researcher Alon Leviev disclosed a novel "Windows Downdate" downgrade attack using two zero-day vulnerabilities (CVE-2024-38202, CVE-2024-21302) that can force fully patched Windows 10/11 and Server systems to revert critical components (DLLs, kernel, VBS/Hyper-V components) to older vulnerable versions, bypass UEFI locks and make systems susceptible to thousands of past vulnerabilities; Microsoft published advisories and is developing mitigations but reports no known exploitation in the wild.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.