Windows Policy Loopholes
The MS Windows policy loophole, identified by Cisco Talos, allows threat actors to sign the malicious kernel mode drivers that are executed by the Windows OS. RedDriver malware poses a serious threat to the kernel mode drivers in comparison to user mode drivers.?
Severe threat associated to malicious kernel mode drivers
The kernel mode is more susceptible due to a number of reasons:
Policy changes implemented by Windows
Some of the policy changes that have been brought about Windows Vista limit overall loading of the kernel mode drivers into OS. Also the modifications that have been introduced by Microsoft enable the developer to sign and review drivers through compliance of the esteemed Microsoft's portal.?
Some of the policy exceptions are as follows:
Chinese threat actors manipulate signing date for exploitation of third policy to gain leverage on open source tools such as:
领英推荐
Loophole that is exploited?
For maintenance of overall compatibility and functionality of the older drivers, Microsoft has introduced some of the exceptions that include the following:
Recommendations:
Some of the recommendations that organizations need to follow in order to bypass the security policy loophole of Windows include the following:
Content Writer with 7+ Years Of Experience| Navigating through SEO one step at a time | Crafting Engaging Stories For Brands
1 年Thanks for sharing