HomeHow ToHow to update Windows drivers blocklist?

How to update Windows drivers blocklist?

An investigation revealed that Microsoft's malicious driver blocklist was not being updated as expected.

Here's how you can make sure you don't let bad actors gain access to your system through these carefully crafted attack tools.

For many years, attackers have used a variety of methods to get into our systems. From phishing to tricking us into clicking on websites, if an attacker can inject their code into our systems, they are no longer our systems. Attackers will even invest time, energy, and expense to design malicious drivers through the Windows Hardware Compatibility Program in order to gain access to our machines. Ensuring that these malicious drivers are blocked is a key method for protecting systems.

How to update Windows drivers blocklist?
How to update Windows drivers blocklist?

Microsoft has long touted a way to update this blocklist of malicious drivers on our systems, and the idea was valid: using security settings and hardware on the computer, enabling hypervisor -protected code integrity (HVCI) is supposed to protect systems from malicious drivers. Attackers have used such attacks in the past, and they range from RobbinHood , Uroburos , Derusbi , GrayFish , and Sauron , to campaigns by the STRONTIUM threat actor . As a Microsoft blog post pointed out in 2020, if a computer had HVCI enabled , it could defend itself against vulnerable and malicious drivers. The blog post noted that “Microsoft threat research teams continuously monitor the threat ecosystem and update the list of drivers included in the Microsoft-provided drivers blocklist. This blocklist is pushed to devices through Windows Update .”

See also: Windows 10 KB5018482: Brings 19 fixes and improvements

There’s an oft-used phrase in cybersecurity: “trust but verify.” When Ars Technica security editor Dan Goodin decided to test this setting, he started looking to confirm that the malicious driver blocklist was actually being updated. Expecting to find out that it was, he instead found that it wasn’t. Goodin reached out to researcher Will Dornmann , Senior Vulnerability Analyst at ANALYGENCE , and he confirmed that this feature wasn’t working as expected. Goodin and Dormann found that even with HVCI enabled , the list of vulnerable drivers wasn’t being updated as it should have been. In contrast, on Windows 10, it hadn’t received updates since 2019.

Microsoft recently announced that with the Windows 11 22H2, the vulnerable driver blocklist setting is enabled by default. They stated that: “The driver blocklist is updated with each new major release of Windows. We plan to update the current blocklist for non-Windows 11 in an upcoming release and will occasionally release future updates through regular Windows servicing.” So, they finally admitted that they weren’t serving users as well as we had assumed with Microsoft’s update process.

As a result of Goodwin and Dormann that the drivers blocklist was not being updated, Microsoft provided a guide on how to manually refresh the blocklist. So, if you have relied on the drivers blocklist functionality, we recommend that you add manually updating this drivers blocklist to your to-do list until Microsoft has a process in place to update this drivers blocklist on a regular basis.

How to update Windows drivers blocklist?
How to update Windows drivers blocklist?

As Microsoft states, you can perform the following steps to update the drivers blocklist:

  • Download the WDAC. Select the version you need for your version of Windows (32-bit, 64-bit, or ARM versions).
  • Download and extract the vulnerable drivers blocklist binaries
  • Select either the test-only version or the enforced version and rename the file to SiPolicy.p7b.
  • Copy SiPolicy.p7b to %windir%\system32\CodeIntegrity.
  • Run the WDAC Policy Refresh Tool that you downloaded in Step 1 above to enable and refresh all WDAC policies on your computer.

To check that the policy was successfully applied to your computer:

  • Open Event Viewer.
  • Browse to Applications and Services Logs – Microsoft – Windows – CodeIntegrity – Operational.
  • Select Filter Current Log.
  • Replace " with "3099" and select OK.

Look for a 3099 event where the PolicyNameBuffer and PolicyIdBuffer match the name and ID in the PolicyInfo located at the bottom of the drivers blocklist WDAC Policy XML.

See also: Microsoft: Fixes TLS handshake failures in latest Windows update

You should be able to create a PowerShell to deploy the updated values ​​to your network using similar tools to define WDAC policies on your network. You will need to download the WDAC Policy Refresh Tool to all of endpoints in order to update your entire network.

Will Dormann provides his own independent tool for updating the driver list. To do this, follow these steps:

  • Open CMD.
  • Type powershell_ise.exe to start Powershell ISE.
  • From a Github link, copy and paste (CTRL+A, CTRL+c, and CTRL+v) into Powershell ISE.
  • Type ApplyWDACPpolicy -auto -enforce and press enter.
  • As always, make sure you test it on one computer before rolling it out to the entire company.

While those of us with secure networks want to enforce this driver blocklist, it’s always fascinating to find examples of people intentionally disabling this feature. A prime example is the gaming, which wants to get around malicious driver blocks. Gaming cheats are blocked in Windows 11 22H2, clearly showing that, at least for this platform, the malicious driver block utility works. As they themselves state, “HKLM\System\CurrentControlSet\Control\CI\Config\, then create a new DWORD named VulnerableDriverBlocklistEnable and set it to 0” will bypass the malicious driver block.

How to update Windows drivers blocklist?
How to update Windows drivers blocklist?

You may want to monitor the registry key to ensure that malicious actors do not disable this blocker and leave you exposed. If your organization does not already have a solution for proactively monitoring file and registry changes, you may want to consider using tools like ProcMon or Process Monitor to review changes made over time. However, it is not recommended to run it for 24/7 monitoring. For long-term review of system changes, we recommend running Sysmon.

“ System Monitor (Sysmon) is a Windows and device driver that, once installed on a system, persists across system reboots to monitor and record system activity in the Event log . It provides detailed information about process creations, network connections, and changes in file creation time.” I recommend installing it on servers that have internet access and on any workstations that are at increased risk. You may also consider deploying it to all workstations, as the overhead of the Sysmon running in the background is minimal.

The key thought to keep in mind behind any vendor security program is to trust but verify. It seems that even Microsoft doesn't fully understand its own systems. It's imperative that we do everything we can to better understand them.

In a late change, on October 26, Microsoft released an updated drivers blocklist in a preview update. As noted in KB5020779, this preview build addresses an issue that only updates the drivers blocklist for full versions of the Windows operating system. When you install this build, the drivers blocklist on older versions of the operating system will be the same as the drivers blocklist on Windows 11, version 21H2 and later. This fix will be integrated into the November security updates that will be released on November 8, 2022, and as a result, manually updating using this cumbersome process will no longer be necessary. It is clear that Microsoft understood that this process was not acceptable to protect our machines.

Source: csoonline.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS