Skip to main content

There’s a scary new way to undo Windows security patches

Person sitting and using an HP computer with Windows 11.
Microsoft

Security patches for Windows are essential for keeping your PC safe from developing threats. But downgrade attacks are a way of sidestepping Microsoft’s patches, and a security researcher set out to show just how fatal these can be.

SafeBreach security researcher Alon Leviev mentioned in a company blog post that they’d created something called the Windows Downdate tool as a proof-of concept. The tool crafts persistent and irreversible downgrades on Windows Server systems and Windows 10 and 11 components.

Recommended Videos

Leviev explains that his tool (and similar threats) performs a version-rollback attack, “designed to revert an immune, fully up-to-date software back to an older version. They allow malicious actors to expose and exploit previously fixed/patched vulnerabilities to compromise systems and gain unauthorized access.”

He also mentions that you can use the tool to expose the PC to older vulnerabilities sourced in drivers, DLLs, Secure Kernel, NT Kernel, the Hypervisor, and more. Leviev went on to post the following on X (formerly Twitter): “Other than custom downgrades, Windows Downdate provides easy to use usage examples of reverting patches for CVE-2021-27090, CVE-2022-34709, CVE-2023-21768 and PPLFault, as well as examples for downgrading the hypervisor, the kernel, and bypassing VBS’s UEFI locks.”

If you have not checked it out yet, Windows Downdate tool is live! You can use it to take over Windows Updates to downgrade and expose past vulnerabilities sourced in DLLs, drivers, the NT kernel, the Secure Kernel, the Hypervisor, IUM trustlets and more!https://t.co/59DRIvq6PZ

— Alon Leviev (@_0xDeku) August 25, 2024

What’s also concerning is that the tool is undetectable because it can’t be blocked by endpoint detection and response (EDR) solutions, and your Windows computer will continue to tell you it’s up to date even though it’s not. He also uncovered various ways to turn off Windows virtualization-based security (VBS), including Hypervisor-Protected Code integrity (HVCI) and Credential Guard.

Microsoft released a security update (KB5041773) on August 7 to fix the CVE-2024-21302 Windows Secure Kernel Mode privilege escalation flaw and a patch for CVE-2024-38202. Microsoft has also released some tips Windows users can take to stay safe, such as configuring “Audit Object Access” settings to scan for file access attempts. The release of this new tool shows how exposed PCs are to all sorts of attacks and how you should never let your guard down when it comes to cybersecurity.

The good news is that we can rest easy for now since the tool was created as a proof-of-concept, an example of “white-hat hacking” to discover vulnerabilities before threat actors do. Also, Leviev handed over his findings to Microsoft in February 2024, and hopefully, the software giant will have the necessary fixes soon.

Judy Sanhz
Judy Sanhz is a Digital Trends computing writer covering all computing news. Loves all operating systems and devices.
Microsoft Supercharges AI to fix Windows software bugs
Windows 11 on several devices.

Microsoft is developing an AI system to make detecting and fixing software problems on your Windows 11 PC easier, MSPowerUser reports. The system analyzes error data to resolve issues efficiently, and Microsoft is also working on turning Copilot into a multi-user chat platform.

MSPowerUser recently came across a new patent document with a publication date in February 2025. Specifically, it's a 25-page document that describes how the new system would work. According to the document, the new AI system would detect the issues and suggest or apply solutions to refine the troubleshooting process. Although the AI system is designed for developers, regular users can also benefit by getting automated fixes and smart support. Furthermore, the system can create reports for more complex issues to assist developers in debugging more efficiently.

Read more
Windows 10 KB5051974 update adds a new app without asking
A Dell laptop with Windows 10 sitting on a desk.

Microsoft has released the KB5051974 cumulative update for versions 22H2 and 21H2, adding security fixes and patching a memory leak. However, as Bleeping Computer reports, the update also includes a surprise: the new Outlook for Windows app.

The update is mandatory because it includes the January 2025 Patch Tuesday security updates. Once you install it, you will notice the new app icon near the classic one in the Start Menu's apps section. Since the new app can operate concurrently, you don't have to worry about interfering with the old one.

Read more
Windows 11’s February 2025 update fixes annoying bugs
Windows 11 logo on a laptop.

Microsoft's February 2025 cumulative update brings much-needed relief to Windows 11 users, fixing Auto HDR issues that caused game crashes, audio output disruptions, and USB webcam detection problems, as reported by Bleeping Computer. The patch, KB5051987 for Windows 11 24H2 users and KB5051989 for 23H2 addresses these irritating bugs and is mandatory.

The update fixes the Auto HDR problem that interfered with the colors and caused game crashes, improving the gaming experience. Furthermore, the update fixes a bug that cut off audio output, especially if you were using a digital-to-analog converter (DAC), though others were affected. Moreover, a rare issue displayed a "This device cannot start" message, but you may not have seen that one.

Read more