Skip to main content

This Windows Update exploit is downright terrifying

Windows Update running on a laptop.
Clint Patterson / Unsplash

Windows Update may occasionally backfire with faulty patches, but for the most part, it’s meant to keep us safe from the latest threats. Microsoft regularly pushes new patches that address potential vulnerabilities. But what if there were a tool that could undo every Windows Update and leave your PC exposed to all the threats Microsoft thought it had already fixed? Bad news: Such a tool now exists, and it’s called Windows Downdate.

Don’t worry, though. You’re safe from Windows Downdate — at least for now. The tool was developed as a proof-of-concept by SafeBreach researcher Alon Leviev, and although its potential is nothing short of terrifying, it was made in good faith as an example of something called “white-hat hacking,” where researchers try to find vulnerabilities before malicious threat actors can do it first.

Recommended Videos

In the case of Windows Downdate, if this fell into the wrong hands, the impact could be staggering. The exploit relies on a flaw in Windows Update to install older updates where certain vulnerabilities haven’t been patched yet. Leviev used the tool to downgrade dynamic link libraries (DLL), drivers, and even the NT kernel, which is a core component in Windows. This is achieved while bypassing all verification, and the result is entirely invisible and irreversible.

“I was able to make a fully patched Windows machine susceptible to thousands of past vulnerabilities, turning fixed vulnerabilities into zero-days and making the term ‘fully patched’ meaningless on any Windows machine in the world,” said Leviev in a SafeBreach post. “After these downgrades, the OS reported that it was fully updated and was unable to install future updates, while recovery and scanning tools were unable to detect issues.”

The Windows Downgrade tool.
Alon Leviev / SafeBreach

Leviev also discovered that the entire virtualization stack in Windows was also susceptible to this exploit; the researcher managed to downgrade Credential Guard’s Isolated User Mode Process, Hyper-V’s hypervisor, and Secure Kernel. Leviev even found “multiple ways” to turn off virtualization-based security (VBS) in Windows, and this was still possible even when UEFI locks were enforced.

“To my knowledge, this is the first time VBS’s UEFI locks have been bypassed without physical access,” Leviev said.

Windows Downdate can essentially undo every security patch ever created, then trick the PC into thinking everything is fine as it stealthily exposes it to hundreds of different threats. A tool such as this could wreak some serious havoc on any OS, and Leviev suspects that other operating systems, such as MacOS and Linux, might be at risk as well.

The good news is that Leviev intended to protect Windows users from a tool such as this, and the researcher reported his findings to Microsoft in February 2024. Microsoft issued two CVEs in response (CVE-2024-21302 and CVE-2024-38202) and appears to be hard at work fixing this vulnerability. Let’s hope that Microsoft is quicker to patch this exploit than non-ethical hackers are to use it to their own advantage.

Monica J. White
Monica is a computing writer at Digital Trends, focusing on PC hardware. Since joining the team in 2021, Monica has written…
This beloved Mac-only app has finally come to Windows
iOS 16 Work Focus with a Fantastical widget and two rows of work-related apps

Highly popular (and expensive) calendar app Fantastical has launched a Windows version of its app, finally bringing it out of just the Apple ecosystem 13 years after its initial release.

The calendar has been rebuilt as a native Windows app with all of the features included on Mac, though it doesn't yet have an Arm-native version for Copilot+ PC owners.

Read more
Google Gemini is good, but this update could make it downright sci-fi
Google Gemini running on an Android phone.

Ever since seeing the "Welcome home, sir" scene in Iron Man 2, many of us have wanted a smart setup with a Jarvis-like assistant. While some may have hoped that Alexa would provide that kind of functionality, so far, the assistant is just too limited. That might change with the launch of Gemini 2.0 and Google's Project Jarvis, though.

In a sense, this new project is Jarvis. The system works by taking stills of your screen and interpreting the information on it, including text, images, and even sound. It can auto-fill forms or press buttons for you, too. This project was first hinted at during Google I/O 2024, and according to 9to5Google, it's designed to automate web-based tasks. Jarvis is an AI agent with a narrower focus than a language learning model like ChatGPT — an AI that demonstrates human-like powers of reasoning, planning, and memory.

Read more
Your next Windows update should install much faster
Windows 11 logo on a laptop.

It's about time Windows 11 users got some good news about updates. Microsoft recently claimed in a blog post that thanks to 24H2's servicing stack, the update installs up to 45.6% faster than previous versions of Windows. The upcoming update will use fewer system resources, and the restart time will be faster.

According to Microsoft's tests on PCs that had not been updated for 18 months and ones that were regularly updated, there were significant improvements to celebrate. On the well-maintained PCs, installation time was 45.6% faster, restart time was 39.7% faster, and CPU usage was 15.3% less. In an atypical scenario with an 18-month out-of-date PC, the installation time was 43.6% faster, restart time was 33.5% faster, and CPU usage was 25% less.

Read more