Threat Advisories:

Windows Update Zero-Day Flaws Allow Downgrade Attacks on Patched Systems

Red | Vulnerability Report
Download PDF

Two recently discovered zero-day vulnerabilities in Windows, CVE-2024-38202 and CVE-2024-21302, enable attackers to downgrade systems, removing security updates and exposing them to old exploits. This attack is undetectable, as Windows Update falsely indicates the system is fully patched. Microsoft is working on mitigations, but no fix is available yet, leaving systems at risk.

What’s new on HivePro

Get through updates and upcoming events, and more directly in your inbox

Cyber Horizons 2025

What Last Year’s Attacks Reveal About Today’s Risks

Watch the Webinar on-demand and get a FREE copy of our Cyber Horizons 2025 report.

Our Speakers
Speaker 1

Prateek Bhajanka Global Field CISO & Former Gartner Analyst Hive Pro Inc.

Speaker 2

Ankit Mani Manager Threat Intel HiveForce Labs

Speaker 3

Sreevani Tonipe Senior Threat Researcher HiveForce Labs