Windows Update Zero-Day Flaws Allow Downgrade Attacks on Patched Systems

Red | Vulnerability Report
Download PDF

Two recently discovered zero-day vulnerabilities in Windows, CVE-2024-38202 and CVE-2024-21302, enable attackers to downgrade systems, removing security updates and exposing them to old exploits. This attack is undetectable, as Windows Update falsely indicates the system is fully patched. Microsoft is working on mitigations, but no fix is available yet, leaving systems at risk.

What’s new on HivePro

Get through updates and upcoming events, and more directly in your inbox