HomeSecurityTSforge exploits vulnerabilities in every version of Windows

TSforge exploits vulnerabilities in every version of Windows

Security researchers from MASSGRAVE have uncovered TSforge , an innovative tool that exploits vulnerabilities in Microsoft 's Software Protection Platform (SPP) . Through these vulnerabilities, TSforge can activate any version of Windows , from Windows 7 and later, as well as Office suites and their add-ins.

See also: CISA adds Adobe and Oracle vulnerabilities to KEV list

TSforge

This exploit is the first successful direct attack on SPP's core cryptographic defenses since its integration into Windows Vista. At its core, SPP leverages encrypted "trust stores" to securely and reliably validate activation status.

These stores operate as:

  • data.dat/tokens.dat files (Windows 8+)
  • 7B296FB0-… Registry-supported files (Windows 7)
  • HKLM\SYSTEM\WPA keys (all versions)

The TSforge discovery resulted from reverse engineering the SPP private key infrastructure, leveraging leaks from Windows 8 beta builds

See also: Vulnerabilities in Xerox printers allow credentials to be stolen

MassGrave researchers discovered that modifying these trusted stores with fake activation data — bypassing RSA-2048/AES-CBC— can trick SPP into accepting permanent licenses.

TSforge exploits vulnerabilities in every version of Windows

The exploit relies on obtaining the private RSA production key of SPP, which Microsoft uses to sign activation blobs. By emulating ExecCodes – an obscure bytecode interpreter in sppsvc.exe – the researchers extracted the private exponent via addition-chain exponentiation.

This allowed the decryption of the AES key protecting data.dat. Once decrypted, TSforge injects:

  • Zeroed HWID hashes (B25D3E80…) to bypass hardware fingerprint checks
  • Precomputed product key blobs that mimic KMS/MAK activations
  • License metadata with a timestamp and validity windows of 4000+ years

See also: Hackers used combined vulnerabilities in BeyondTrust and PostgreSQL

The tool's effectiveness is enhanced by its broad compatibility, as it works equally well with the spsys.sys driver architecture in Windows 7 and the unified sppsvc.exe in Windows 10 .

Source: cybersecuritynews

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS