Revealing Windows Update Downgrade Attack: Threats and Protection
At the recent Black Hat conference, SafeBreach researchers disclosed a new Windows update downgrade attack (also known as version rollback attack), which attracted widespread attention. This attack can roll back updated software to older versions, causing serious damage to system components, software, and files.
Attack principle and impact
Attackers can manipulate Windows Update to downgrade DLLs, drivers, and even critical operating system components such as NT kernels. This invalidates all installed security patches, bypassing security features and increasing system permissions. SafeBreach practice shows that after this attack, the system cannot recognize new security updates and errors are reported as the latest version, and the infection cannot be detected by the recovery and scanning tools. In short, this attack can lead to serious data breaches and other consequences. For more technical details, please refer to the SafeBreach report: Windows Downgrade Attacks via Windows Update.
Microsoft has released vulnerability information
Microsoft has not released an update that completely fixes this vulnerability, but has released two CVEs (CVE-2024-38202 and CVE-2024-21302) to reduce the risk. You can visit the relevant website and take corresponding measures according to the instructions.
Related suggestions include configuring the audit object access settings, auditing users with backup and restore operation permissions, and implementing access control lists.
Daily protective measures
To prevent such attacks, we recommend that you:
- Avoid downloading applications or software from unreliable sources.
- Use network security measures such as Windows firewall to monitor and filter network traffic.
- Do not access suspicious links or compressed files at will.
- Even if there is a downgrade attack, the system should be kept updated, which helps prevent virus and malware intrusions and improves system performance.
- Regularly back up important files to external hard drives. It is recommended to use professional backup software such as MiniTool ShadowMaker.
Data recovery suggestions
Computer attacks often cause data loss. If you need to recover deleted or lost data on your Windows computer, you can use MiniTool Power Data Recovery. This is a safe and reliable data recovery software that can recover various files without damaging the original data. The software is available in a free version and supports free downloads, disk scanning, file preview and 1GB of free data recovery.
Summarize
This article briefly introduces Windows update downgrade attacks, including its principles, impacts, and some common security protection measures. I hope this information can help you better protect your computer's security.
The above is the detailed content of Windows Update Downgrade Attack Rolls Back Updates. For more information, please follow other related articles on the PHP Chinese website!

If you want to buy a top printer & scanner, this post lists some best printers and scanners and copiers including some top HP printers and scanners. php.cn Software not only provides useful computer software but also provides various computer tut

You can use the built-in Network Adapter troubleshooter in Windows 11 to find and fix problems with wireless and other network adapters. This post teaches you how to find and run Windows 11 network adapter troubleshooter with detailed instructions. S
![[Solved] Battlefield 2042 Black Screen Issues (7 Solutions) - MiniTool](https://img.php.cn/upload/article/001/242/473/174698221230413.png?x-oss-process=image/resize,p_40)
Battlefield 2042 black screen then crash is an annoying problem when gaming. How to fix it? This guide on php.cn Website aims at tackling this issue. Look it through carefully and we sincerely hope that our solutions will work fine for you.

Have you ever encountered Dev Error 11557 in Call of Duty: Modern Warfare 2 or Warzone 2? If you are, you come to the right place. In this post, php.cn provides some potential solutions to help you fix this error.

If you want to cancel your Apple Music subscription, there are several ways to do so. This post from php.cn tells you how to cancel your subscription using your iPhone, iPad, Android device, Mac, or the Apple TV.

Microsoft 365 offers several subscription plans for you to choose from. This post introduces and compares all Microsoft 365 plans. You can choose a preferred Microsoft 365 plan based on your own needs. To recover deleted or lost files like Office fil

The VLC media player is a free and open-source, portable, cross-platform media player software and streaming media server, which is available for desktop operating systems and mobile platforms. But some people find the “VLC not playing videos” issue

To manage your daily tasks, you can use the free task management app - Microsoft To Do. This post teaches you how to download Microsoft To Do on Windows 10/11, Mac, iPhone/iPad, or Android. If you are looking for more computer tips and solutions, you


Hot AI Tools

Undresser.AI Undress
AI-powered app for creating realistic nude photos

AI Clothes Remover
Online AI tool for removing clothes from photos.

Undress AI Tool
Undress images for free

Clothoff.io
AI clothes remover

Video Face Swap
Swap faces in any video effortlessly with our completely free AI face swap tool!

Hot Article

Hot Tools

VSCode Windows 64-bit Download
A free and powerful IDE editor launched by Microsoft

mPDF
mPDF is a PHP library that can generate PDF files from UTF-8 encoded HTML. The original author, Ian Back, wrote mPDF to output PDF files "on the fly" from his website and handle different languages. It is slower than original scripts like HTML2FPDF and produces larger files when using Unicode fonts, but supports CSS styles etc. and has a lot of enhancements. Supports almost all languages, including RTL (Arabic and Hebrew) and CJK (Chinese, Japanese and Korean). Supports nested block-level elements (such as P, DIV),

MantisBT
Mantis is an easy-to-deploy web-based defect tracking tool designed to aid in product defect tracking. It requires PHP, MySQL and a web server. Check out our demo and hosting services.

Notepad++7.3.1
Easy-to-use and free code editor

SAP NetWeaver Server Adapter for Eclipse
Integrate Eclipse with SAP NetWeaver application server.
