Skip to main content

There’s a scary new way to undo Windows security patches

Person sitting and using an HP computer with Windows 11.
Microsoft

Security patches for Windows are essential for keeping your PC safe from developing threats. But downgrade attacks are a way of sidestepping Microsoft’s patches, and a security researcher set out to show just how fatal these can be.

SafeBreach security researcher Alon Leviev mentioned in a company blog post that they’d created something called the Windows Downdate tool as a proof-of concept. The tool crafts persistent and irreversible downgrades on Windows Server systems and Windows 10 and 11 components.

Recommended Videos

Leviev explains that his tool (and similar threats) performs a version-rollback attack, “designed to revert an immune, fully up-to-date software back to an older version. They allow malicious actors to expose and exploit previously fixed/patched vulnerabilities to compromise systems and gain unauthorized access.”

He also mentions that you can use the tool to expose the PC to older vulnerabilities sourced in drivers, DLLs, Secure Kernel, NT Kernel, the Hypervisor, and more. Leviev went on to post the following on X (formerly Twitter): “Other than custom downgrades, Windows Downdate provides easy to use usage examples of reverting patches for CVE-2021-27090, CVE-2022-34709, CVE-2023-21768 and PPLFault, as well as examples for downgrading the hypervisor, the kernel, and bypassing VBS’s UEFI locks.”

If you have not checked it out yet, Windows Downdate tool is live! You can use it to take over Windows Updates to downgrade and expose past vulnerabilities sourced in DLLs, drivers, the NT kernel, the Secure Kernel, the Hypervisor, IUM trustlets and more!https://t.co/59DRIvq6PZ

— Alon Leviev (@_0xDeku) August 25, 2024

What’s also concerning is that the tool is undetectable because it can’t be blocked by endpoint detection and response (EDR) solutions, and your Windows computer will continue to tell you it’s up to date even though it’s not. He also uncovered various ways to turn off Windows virtualization-based security (VBS), including Hypervisor-Protected Code integrity (HVCI) and Credential Guard.

Microsoft released a security update (KB5041773) on August 7 to fix the CVE-2024-21302 Windows Secure Kernel Mode privilege escalation flaw and a patch for CVE-2024-38202. Microsoft has also released some tips Windows users can take to stay safe, such as configuring “Audit Object Access” settings to scan for file access attempts. The release of this new tool shows how exposed PCs are to all sorts of attacks and how you should never let your guard down when it comes to cybersecurity.

The good news is that we can rest easy for now since the tool was created as a proof-of-concept, an example of “white-hat hacking” to discover vulnerabilities before threat actors do. Also, Leviev handed over his findings to Microsoft in February 2024, and hopefully, the software giant will have the necessary fixes soon.

Judy Sanhz
Computing Writer
Judy Sanhz is a Digital Trends computing writer covering all computing news. Loves all operating systems and devices.
Windows 11 and 10 users find new inetpub folder after April update
Shutdown menu in Windows 11.

Windows 11 and 10 users have reported a mysterious 'inetpub' folder after installing Microsoft's April 2025 updates, as Bleeping Computer reports. Although the folder is typically associated with the Internet Information Services (IIS) web server, it's now appearing on systems without it installed. Microsoft has confirmed that the behavior is intentional but has not fully explained why.

The unexpected folder is empty, and you can find it in the root of the C: drive even if you don't have IIS installed. If you had IIS installed (web server platform by Microsoft), it would use the inetpub folder to save logs, website content, and server-related files. So, it's weird you have one without the other after installing Windows 11 KB5055523 update or Windows 10 KB5055518. The SYSTEM account owns the new inetpub folder, meaning an elevated process made it.

Read more
Google Drive, iCloud, or OneDrive: Which cloud storage is most private and secure?
Google Drive, iCloud, and OneDrive are open on a PC monitor.

Cloud storage is convenient, syncing your files and photos between devices, but is it secure enough to keep your data safe? And how much private information are you sharing when you use Microsoft OneDrive, Apple iCloud, and Google Drive?

If you’re paying for the best antivirus software to protect your computer, you want to safeguard your data that’s in the cloud. Likewise, the best VPNs hide your identity, but some cloud storage providers lack the end-to-end encryption that ensures privacy.
Cloud security

Read more
I hope these 3 long-lost Microsoft Windows 8 features stay gone forever
Windows 8 Start screen

If you used a Windows computer in the early 2010s, chances are you experienced Windows 8. Whether it was a good experience is another matter entirely, though. If you ask me, it was a bit of a disaster.

For me, updating to Windows 8 was an unexpected jumpscare. Maybe you had a similar experience; perhaps you just updated your computer one day to discover that the beloved Start Menu vanished without warning. In its place, you saw a full-screen tile interface that probably made you feel like you were using a phone rather than a desktop.

Read more