Skip to main content

This Windows Update exploit is downright terrifying

Windows Update running on a laptop.
Clint Patterson / Unsplash

Windows Update may occasionally backfire with faulty patches, but for the most part, it’s meant to keep us safe from the latest threats. Microsoft regularly pushes new patches that address potential vulnerabilities. But what if there were a tool that could undo every Windows Update and leave your PC exposed to all the threats Microsoft thought it had already fixed? Bad news: Such a tool now exists, and it’s called Windows Downdate.

Don’t worry, though. You’re safe from Windows Downdate — at least for now. The tool was developed as a proof-of-concept by SafeBreach researcher Alon Leviev, and although its potential is nothing short of terrifying, it was made in good faith as an example of something called “white-hat hacking,” where researchers try to find vulnerabilities before malicious threat actors can do it first.

Recommended Videos

In the case of Windows Downdate, if this fell into the wrong hands, the impact could be staggering. The exploit relies on a flaw in Windows Update to install older updates where certain vulnerabilities haven’t been patched yet. Leviev used the tool to downgrade dynamic link libraries (DLL), drivers, and even the NT kernel, which is a core component in Windows. This is achieved while bypassing all verification, and the result is entirely invisible and irreversible.

“I was able to make a fully patched Windows machine susceptible to thousands of past vulnerabilities, turning fixed vulnerabilities into zero-days and making the term ‘fully patched’ meaningless on any Windows machine in the world,” said Leviev in a SafeBreach post. “After these downgrades, the OS reported that it was fully updated and was unable to install future updates, while recovery and scanning tools were unable to detect issues.”

The Windows Downgrade tool.
Alon Leviev / SafeBreach

Leviev also discovered that the entire virtualization stack in Windows was also susceptible to this exploit; the researcher managed to downgrade Credential Guard’s Isolated User Mode Process, Hyper-V’s hypervisor, and Secure Kernel. Leviev even found “multiple ways” to turn off virtualization-based security (VBS) in Windows, and this was still possible even when UEFI locks were enforced.

“To my knowledge, this is the first time VBS’s UEFI locks have been bypassed without physical access,” Leviev said.

Windows Downdate can essentially undo every security patch ever created, then trick the PC into thinking everything is fine as it stealthily exposes it to hundreds of different threats. A tool such as this could wreak some serious havoc on any OS, and Leviev suspects that other operating systems, such as MacOS and Linux, might be at risk as well.

The good news is that Leviev intended to protect Windows users from a tool such as this, and the researcher reported his findings to Microsoft in February 2024. Microsoft issued two CVEs in response (CVE-2024-21302 and CVE-2024-38202) and appears to be hard at work fixing this vulnerability. Let’s hope that Microsoft is quicker to patch this exploit than non-ethical hackers are to use it to their own advantage.

Monica J. White
Monica is a computing writer at Digital Trends, focusing on PC hardware. Since joining the team in 2021, Monica has written…
Microsoft is fixing my biggest problem with Windows 11 on handhelds
Asus ROG Ally with the Windows lock screen.

We're finally starting to make some progress on the handheld experience of Windows 11. Although Windows 11 handhelds like the ROG Ally X are some of the best handheld gaming PCs you can buy, that's despite their use of Windows, not because of it. Now, the latest Windows 11 Insider preview (build 22631.4387) adds a feature that should make navigating the OS much easier on a handheld -- a keyboard built for gamepads.

Windows has included an onscreen keyboard for years, and updates over the last couple of years have even made it usable with touch inputs. On a handheld, however, there are two problems with the keyboard. You can't invoke it naturally -- you have to bind Windows + Ctrl + O to a hotkey -- and you can't use your controller to navigate it. With the new update, Microsoft is fixing that last point, at the very least.

Read more
Windows 11 is creating an ‘undeletable’ 8.63GB cache
The Surface Pro 11 on a white table in front of a window.

The recent Windows 11 24H2 update is reportedly flawed with a new issue where it creates 8.63GB of undeletable update cache. This cache is made during the update process and seems to remain on the system, despite attempts to remove it using traditional methods like Disk Cleanup, Storage Sense, or even manually deleting system folders like Windows.old​.

The issue appears to be linked to checkpoint updates, a new feature in Windows 11 designed to streamline and shrink update sizes by downloading smaller patches rather than full updates.

Read more
Passkeys in Windows 11 are about to get safer and easier to use
Customer using 1Password on their Windows laptop, sitting on a couch.

According to a new Developer Blog post, Microsoft is expanding its support for passkeys on Windows 11 soon, with plans to let you choose how your passkeys are saved and where they're stored. A new API will also allow third-party password managers like 1Password or Bitwarden to integrate more seamlessly into the Windows passkey experience.

With Windows Hello, users will be prompted to complete a one-time setup for each passkey-friendly website using their Microsoft account. Once that's done, you can log in across all your Windows 11 devices using whichever authentication method you prefer -- PIN, fingerprint, or facial recognition. All passkeys will be secured with end-to-end encryption and use your PC's TPM (Trusted Platform Module) to keep them protected.

Read more