logo

Downgrade attacks open patched systems to malware

ID: 48486a45-8af1-5276-b76e-bee5e5dbba98

STIX ID: report--48486a45-8af1-5276-b76e-bee5e5dbba98

Feed Name: ReversingLabs Blog

Threat Score
72/100

Date Published: 2024-11-06

Date Updated: 2026-04-29

Author: [email protected] (Paul Roberts)

...
...

Research by Alon Leviev demonstrates that Windows downgrade attacks can revert patched components (DLLs, drivers, kernel) to vulnerable versions, allowing unsigned kernel drivers and privilege escalation; while Microsoft patched specific CVEs (CVE-2024-21302 and CVE-2024-38202), the report warns of structural detection gaps and broader risks across platforms.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.