Friday, September 22, 2023
  • About Us
  • Contact Us
  • Write for Us
Digital Tech Blog
  • Home
  • News
  • Tech
  • Business
  • Cryptocurrency
  • Lifestyle
  • Contact Us
  • Write for Us
No Result
View All Result
Digital Tech Blog
  • Home
  • News
  • Tech
  • Business
  • Cryptocurrency
  • Lifestyle
  • Contact Us
  • Write for Us
No Result
View All Result
Digital Tech Blog
No Result
View All Result
Home Business

Microsoft’s out-of-date driver list left Windows PCs open to malware attacks for years

585
SHARES
3.2k
VIEWS
Share on FacebookShare on Twitter


Microsoft failed to properly protect Windows PCs from malicious drivers for nearly three years, according to a report from the Ars Technica. Although Microsoft says its Windows updates add new malicious drivers to a block list downloaded from devices, Ars Technica I found that these updates never actually stuck.

This gap in coverage left users vulnerable to a particular type of attack called BYOVD, or bring your own vulnerable driver. Drivers are the files that your computer’s operating system uses to communicate with external devices and hardware, such as a printer, graphics card, or webcam. Because drivers access the core of the device’s operating system, or kernel, Microsoft requires that all drivers be digitally signed, which proves that they are safe to use. But if an existing, digitally signed driver has a security hole, hackers can exploit it and gain direct access to Windows.

As noted by Ars Technica, Microsoft uses something called hypervisor-protected code integrity (HVCI) to protect against malicious drivers, which the company says is enabled by default on certain Windows devices. But both Ars Technica and Will Dorman, senior vulnerability analyst at cybersecurity company Analysisnce, found that this feature did not provide adequate protection against malicious drivers.

IN thread posted on Twitter in September, Dorman explains that he was able to successfully download a malicious driver to an HVCI-enabled device, even though the driver was on Microsoft’s block list. He later discovered that Microsoft’s block list had not been updated since 2019, and that Microsoft’s Attack Surface Reduction (ASR) capabilities also did not protect against malicious drivers. This means that all HVCI-enabled devices have not been protected from bad drivers for about three years.

Microsoft did not address Dorman’s findings until earlier this month. “We’ve updated the online documentation and added a download with instructions for directly applying the binary,” Microsoft project manager Jeffrey Sutherland said in response to Dorman’s tweets. “We are also fixing issues with our servicing process that prevented devices from receiving policy updates.” Microsoft has since provided instructions on how to manually update the blocked driver list with the vulnerable drivers that have been missing for years, but it still hasn’t clear when Microsoft will automatically start adding new drivers to the list via Windows Updates.

“The list of vulnerable drivers is updated regularly, but we have received feedback that there is a gap in the synchronization between versions of the operating system,” a Microsoft spokesperson said in a statement to Ars Technica. “We have fixed this and it will be serviced in upcoming and future Windows updates. The documentation page will be updated as new updates are released.” Microsoft did not immediately respond On the edgerequest for comment.



Share this:

  • Click to share on Facebook (Opens in new window)
  • Click to share on Twitter (Opens in new window)
  • Click to share on Pinterest (Opens in new window)
  • Click to share on LinkedIn (Opens in new window)
  • Click to share on Tumblr (Opens in new window)
Previous Post

What happens in our brains on a scary Halloween night?

Next Post

For GM auto union workers, there’s still a lot to learn about the electric car industry

admin

admin

Related Posts

Home prices continue to rise with ‘striking’ regional differences, says S&P Case Schiller
Business

Home prices continue to rise with ‘striking’ regional differences, says S&P Case Schiller

by admin
July 25, 2023
Johnson & Johnson is reducing its stake in Kenvue by at least 80% with the swap offer
Business

Johnson & Johnson is reducing its stake in Kenvue by at least 80% with the swap offer

by admin
July 24, 2023
The Space Force raises the stakes as rocket companies compete for lucrative military missions
Business

The Space Force raises the stakes as rocket companies compete for lucrative military missions

by admin
July 22, 2023
The CEO of Kenvue says that consumers are spending on branded health products even when they are declining in other areas
Business

The CEO of Kenvue says that consumers are spending on branded health products even when they are declining in other areas

by admin
July 21, 2023
How BMW uses artificial intelligence to make car assembly more efficient
Business

How BMW uses artificial intelligence to make car assembly more efficient

by admin
July 21, 2023
Next Post
For GM auto union workers, there’s still a lot to learn about the electric car industry

For GM auto union workers, there's still a lot to learn about the electric car industry

Please login to join discussion

Recommended

The mystery of the far side of the moon, explained by a massive blow to the South Pole

The mystery of the far side of the moon, explained by a massive blow to the South Pole

April 10, 2022
How Crypto finances Ukraine’s resistance against Russia

How Crypto finances Ukraine’s resistance against Russia

March 4, 2022

Categories

  • Business
  • Cryptocurrency
  • Entertainment
  • News
  • Tech

Don't miss it

FTC sues Texas anesthesiology provider to bust monopoly
News

FTC sues Texas anesthesiology provider to bust monopoly

September 21, 2023
Amazon leaders were “okay” with people being secretly signed up for Prime, lawsuit alleges
News

Amazon leaders were “okay” with people being secretly signed up for Prime, lawsuit alleges

September 20, 2023
Temple University Says Acting President JoAnne A. Epps Has Died After Collapsing On Stage
News

Temple University Says Acting President JoAnne A. Epps Has Died After Collapsing On Stage

September 19, 2023
McCarthy’s Plan to Avoid a Shutdown Hits Stiff G.O.P. Opposition
News

McCarthy’s Plan to Avoid a Shutdown Hits Stiff G.O.P. Opposition

September 18, 2023
Billionaire investor Mark Cuban loses $870K in crypto scam
News

Billionaire investor Mark Cuban loses $870K in crypto scam

September 17, 2023
Oracle founder Larry Ellison makes first-ever trip to Microsoft headquarters for cloud announcement
News

Oracle founder Larry Ellison makes first-ever trip to Microsoft headquarters for cloud announcement

September 15, 2023
Digital Tech Blog

Digital Tech Blog is the fastest growing blogging and article sharing platform where you can read interesting technology blogs and other informative articles related to business, news, cryptocurrency, lifestyle, and various other categories to read.

Categories

  • Business
  • Cryptocurrency
  • Entertainment
  • News
  • Tech

Recent News

FTC sues Texas anesthesiology provider to bust monopoly

FTC sues Texas anesthesiology provider to bust monopoly

September 21, 2023
Amazon leaders were “okay” with people being secretly signed up for Prime, lawsuit alleges

Amazon leaders were “okay” with people being secretly signed up for Prime, lawsuit alleges

September 20, 2023
  • Contact Us
  • Write for Us
  • Privacy Policy
  • Disclaimer

Copyright © 2021-2023 Digital Tech Blog All Rights Reserved.

No Result
View All Result
  • Home
  • News
  • Tech
  • Business
  • Cryptocurrency
  • Lifestyle
  • Contact Us
  • Write for Us

Copyright © 2021-2023 Digital Tech Blog All Rights Reserved.