
DEF CON 32 - Windows Downdate: Downgrade Attacks Using Windows Updates - Alon Leviev
Source: YouTube · DEFCONConference · published Oct 16, 2024 · 35:19
Downgrade attacks on Windows can bypass critical security features like Secure Boot and Virtualization-Based Security (VBS), enabling full privilege escalation from administrator to kernel level. 1:51
Key Takeaways:
• Windows Update’s update folder integrity checks are flawed, allowing attackers to embed downgrading actions in update files; this enables undetectable, persistent, and irreversible downgrades 3:58–4:49.
• By exploiting a vulnerability in the Windows Update action list path, attackers can modify update actions to downgrade critical components like kernel drivers, leading to kernel code execution 10:00–12:53.
• The hypervisor in VBS can be downgraded via Windows Update, bypassing all security boundaries and compromising the entire virtualization stack 27:00–29:00.
• A flaw in the Windows.old folder allows unprivileged users to replace system backups, enabling downgrades during OS restoration 31:00–31:11.
Downgrade attacks render "fully patched" systems meaningless, exposing thousands of old vulnerabilities to exploitation. 34:50
Sources:
- 1:51 Description of downgrade attack as a method to bypass Secure Boot and exploit known vulnerabilities.
- 3:58–4:49 Analysis of Windows Update’s integrity checks and the exploit of the action list path.
- 10:00–12:53 Demonstration of downgrading a kernel driver and achieving kernel code execution.
- 27:00–29:00 Proof of hypervisor downgrade, b
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
good all right hello everyone and welcome to my talk today I'm going to share with you my journey of researching downgrade attacks on Windows and their severe implications on windows's platform security my name is Alon and I'm a security researcher at safe bridge I'm 22 years old and M selftaught my focus reside in operating system internals reverse engineering and vulnerability research and before joining the security field I was a professional Brazilian G2 athlete where I won several world and European titles this is what I will be talking about today we have a lot of interesting topics to cover so let's Jump Right In starting with the research background so first things first what are DW attacks downgrade downgrade attack is the act of downgrading immune and fully upto-date software to …