Microsoft Reportedly Left Users Vulnerable for Years Due to Out-of-Date Driver List: All Details

Microsoft's blocklist for vulnerable drivers was reportedly out-of-date since 2019.

Advertisement
Written by Radhika Parashar, Edited by David Delima | Updated: 17 October 2022 17:51 IST
Highlights
  • Microsoft reportedly said it has corrected the security flaw
  • The software giant adds malicious drivers for Windows to a blocklist
  • Microsoft's security flaw allowed hackers to use vulnerable drivers

Microsoft reportedly added additional security layers of driver protection

Photo Credit: Reuters

Microsoft failed to safeguard Windows PC users from malicious drivers since 2019, according to a report. Computers use drivers to communicate with external devices such as hard disks, cameras, printers, and smartphones. Each driver is required to be digitally signed to ensure that it is safe for use. If, however, an existing digitally signed driver has a security flaw, it could be easily exploited by hackers. This has reportedly caused people to be exposed to a type of cyberattack called Bring Your Own Vulnerable Driver (BYOVD) that grants hackers direct access to the PCs running on Windows, by exploiting known flaws in driver software.

Microsoft uses hypervisor-protected code integrity (HVCI) as a security measure against such attacks. Citing senior vulnerability analyst Will Dormann, ArsTechnica reports that this security tool did not properly protect users against being infected through compromised drivers.

Last month, Dormann posted a Twitter thread on how he was able to download a malicious driver on a Microsoft HVCI-enabled device, which should have been blocked. He claims that the blocklist had not been updated since 2019, implying that users were not protected by Microsoft from these drivers for years.

Advertisement

Earlier this month, Microsoft project manager Jeffery Sutherland replied to Dormann's tweets and revealed additional protectional measures the company had recently undertaken to mitigate the issue. “We have updated the online docs and added a download with instructions to apply the binary version directly,” Sutherland tweeted.

Advertisement

Microsoft told ArsTechnica that it adds malicious drivers to a blocklist, that receives regular updates. “The vulnerable driver list is regularly updated, however we received feedback there has been a gap in synchronization across OS versions. We have corrected this and it will be serviced in upcoming and future Windows Updates. The documentation page will be updated as new updates are released,” the company said.

Meanwhile many cases of BYOVD attacks have made it to the headlines in recent times. Recently, cybercriminals exploited a vulnerability in the anti-cheat driver for the game Genshin Impact. Last year, North Korean hacking group Lazarus used a BYOVD attack on an aerospace employee in the Netherlands.

Advertisement


Apple unveiled eight new products at its September 'Far Out' event. Which ones will float — and which will sink? We discuss this on Orbital, the Gadgets 360 podcast. Orbital is available on Spotify, Gaana, JioSaavn, Google Podcasts, Apple Podcasts, Amazon Music and wherever you get your podcasts.
Affiliate links may be automatically generated - see our ethics statement for details.
 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: Microsoft, Security Breach, Drivers
Advertisement

Related Stories

Popular Mobile Brands
  1. Xiaomi 17 Ultra Launching Today: All You Need to Know
  2. Realme 16 Pro+ 5G Retail Box Reveals Price in India Weeks Before Launch
  3. OnePlus Nord 6 Visits Certification Website, Could Launch Soon
  4. Rajini Gaang OTT Release Date: Know When and Where to Watch it Online
  5. De De Pyaar De 2 OTT Release: Know Everything About This Ajay Devgan Starrer Romance Comed
  6. Tere Ishk Mein OTT Release Date Reportedly Revealed: When and Where to Watch it Online??
  1. Why Venus Is the Brightest Morning Star Visible From Earth
  2. Oppo Pad Air 5 Launched With 10,050mAh Battery, 12.1-Inch Display: Price, Specifications
  3. Dracula: A Love Tale Now Available For Streaming Online: What You Need to About its Plot, Cast, and More
  4. Xiaomi 17 Ultra Launching Today: Know Price, Features, Specifications and More
  5. South Korean Startup Innospace Fails on First Orbital Launch Attempt of Hanbit-Nano Rocket
  6. Failing Starlink Satellite Photographed in Orbit Before Fiery Reentry
  7. Russia Patents Rotating Space Station Concept to Generate Artificial Gravity in Orbit
  8. Interstellar Comet 3I/ATLAS Shows Wobbling Jets in Rare Sun-Facing Tail, Surprising Astronomers
  9. Magnetic Control of Lithium Enables Safer, High-Capacity “Dream Battery” Without Explosion Risk
  10. Vritta OTT Release Date Revealed: Know When and Where to Watch it Online
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.