Security researchers from MASSGRAVE have uncovered TSforge , an innovative tool that exploits vulnerabilities in Microsoft 's Software Protection Platform (SPP) . Through these vulnerabilities, TSforge can activate any version of Windows , from Windows 7 and later, as well as Office suites and their add-ins.
See also: CISA adds Adobe and Oracle vulnerabilities to KEV list

This exploit is the first successful direct attack on SPP's core cryptographic defenses since its integration into Windows Vista. At its core, SPP leverages encrypted "trust stores" to securely and reliably validate activation status.
These stores operate as:
- data.dat/tokens.dat files (Windows 8+)
- 7B296FB0-… Registry-supported files (Windows 7)
- HKLM\SYSTEM\WPA keys (all versions)
The TSforge discovery resulted from reverse engineering the SPP private key infrastructure, leveraging leaks from Windows 8 beta builds
See also: Vulnerabilities in Xerox printers allow credentials to be stolen
MassGrave researchers discovered that modifying these trusted stores with fake activation data — bypassing RSA-2048/AES-CBC— can trick SPP into accepting permanent licenses.

The exploit relies on obtaining the private RSA production key of SPP, which Microsoft uses to sign activation blobs. By emulating ExecCodes – an obscure bytecode interpreter in sppsvc.exe – the researchers extracted the private exponent via addition-chain exponentiation.
This allowed the decryption of the AES key protecting data.dat. Once decrypted, TSforge injects:
- Zeroed HWID hashes (B25D3E80…) to bypass hardware fingerprint checks
- Precomputed product key blobs that mimic KMS/MAK activations
- License metadata with a timestamp and validity windows of 4000+ years
See also: Hackers used combined vulnerabilities in BeyondTrust and PostgreSQL
The tool's effectiveness is enhanced by its broad compatibility, as it works equally well with the spsys.sys driver architecture in Windows 7 and the unified sppsvc.exe in Windows 10 .
Source: cybersecuritynews
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
