Microsoft is finally cutting down on this list of dodgy Windows drivers

A Microsoft Surface laptop against a white bacground

Microsoft keeps a list of old and vulnerable drivers, which threat actors can use to sneak viruses, ransomware, and other malware into endpoints of their choosing. 

However, the last update was in 2019 - until now. After two years of sitting idly, the list has finally been updated - but not for all Windows users at once, though.

In an announcement published on the company blog, Microsoft said that the blocklist used by the hypervisor-protected code integrity (HVCI) tool will, from now on, be updated once or twice a year. 

More ways to update

“The blocklist is updated with each new major release of Windows, typically 1-2 times per year, including most recently with the Windows 11 2022 update released in September 2022,” Microsoft said. “The most current blocklist is now also available for Windows 10 20H2 and Windows 11 21H2 users as an optional update from Windows Update. Microsoft will occasionally publish future updates through regular Windows servicing.”

Users who always want the latest update to the driver blocklist can use Windows Defender Application Control (WDAC) to apply the latest blocklist, the company further stated. For the sake of convenience, the company provided a download of the most up-to-date vulnerable driver blocklist, as well as instructions on how to apply it, found here.

Microsoft has been getting a lot of criticism lately for the lack of updates to the vulnerable driver blocklist - mainly because the number of attacks using this method skyrocketed. 

The method is called Bring Your Own Vulnerable Driver (BYOVD), and it’s quite a simple thing: a threat actor would trick a victim, usually through social engineering or phishing, into downloading a Windows driver that’s known for being faulty. 

Being a signed driver, it doesn’t trigger any antivirus or endpoint protection services alarms. It just installs like any other non-malicious thing. The driver, being flawed, gives the hackers access to the device, which they can later use for any other attack they see fit - ransomware, botnets, data exfiltration, etc. 

Via: The Register

TOPICS

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
Representational image of a cybercriminal
Microsoft discovers five potentially damaging attacks against its own software
A computer being guarded by cybersecurity.
Huge cyberattack found hitting vulnerable Microsoft-signed legacy drivers to get past security
A laptop with the Windows 11 desktop on screen, glowing, while on a work desk
Are you unable to get security updates for Windows 11 24H2? Here’s the likely reason why, and the fix to get your PC safe and secure again
A hacker wearing a hoodie sitting at a computer, his face hidden.
Microsoft patches three worrying security flaws in its latest critical update, so update now
Woman gaming on a computer at home
Microsoft finally fixes some of Windows 11’s most annoying problems with new patch
Copilot on a laptop
Microsoft quietly updates Copilot to cut down on unauthorized Windows activations
Latest in Software & Services
TinEye website
I like this reverse image search service the most
A person in a wheelchair working at a computer.
Here’s a free way to find long lost relatives and friends
A white woman with long brown hair in a ponytail looks down at her computer in a distressed manner. She is holding her forehead with one hand and a credit card with the other
This people search finder covers all the bases, but it's not perfect
That's Them home page
Is That's Them worth it? My honest review
woman listening to computer
AWS vs Azure: choosing the right platform to maximize your company's investment
A person at a desktop computer working on spreadsheet tables.
Trello vs Jira: which project management solution is best for you?
Latest in News
Cassian Andor looking nervously over his shoulder in Andor season 2
New Andor season 2 trailer has got Star Wars fans asking the same question – and it includes an ominous call back to Rogue One's official teaser
23andMe
23andMe is bankrupt and about to sell your DNA, here's how to stop that from happening
A phone showing a ChatGPT app error message
ChatGPT was down for many – here's what happened
AirPods Max with USB-C in every color
Apple's AirPods Max with USB-C will get lossless audio in April, but you'll need to go wired
A woman sitting in a chair looking at a Windows 11 laptop
It looks like Microsoft might have thought better about banishing Copilot AI shortcut from Windows 11
Lock on Laptop Screen
Medusa ransomware is able to disable anti-malware tools, so be on your guard