A Flaw in Windows Update Opens the Door to Zombie Exploits
ID: 5fa37ba4-46ba-5002-8e9e-92d5e7638f1f
STIX ID: report--5fa37ba4-46ba-5002-8e9e-92d5e7638f1f
Feed Name: WIRED Security
Research presented at Black Hat describes a Windows Update vulnerability (“Downdate”) discovered by SafeBreach Labs that lets an attacker manipulate the update action list (via an unlocked PoqexecCmdline key) to downgrade Windows components and security mechanisms — including drivers, DLLs, the NT kernel, VBS, Secure Kernel, Credential Guard and the hypervisor — thereby exposing known, patched vulnerabilities and enabling potential kernel-level compromise; Microsoft is working on a complex patch process.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
