Dejkala
No Result
View All Result
  • Home
  • Tech
  • Banking & loan
  • Games
  • Car’s & Bike’s
  • Home
  • Tech
  • Banking & loan
  • Games
  • Car’s & Bike’s
No Result
View All Result
Dejkala
No Result
View All Result
Home Latest update

Next Windows 10/11 Patch Tuesday fixes Microsoft’s botched vulnerable driver blocklist- Dejkala

by hasibul
October 27, 2022
in Latest update
0
Next Windows 10/11 Patch Tuesday fixes Microsoft’s botched vulnerable driver blocklist- Dejkala
0
VIEWS
Share on FacebookShare on Twitter


Microsoft building

Image: Getty Images

Microsoft has released a new non-security preview of November’s Patch Tuesday update for Windows 10 and Windows 11 22H2. It brings improvements to the taskbar, Microsoft Account, and Task Manager, as well as a fix for a serious Microsoft blunder that left a hole in the Windows 10 vulnerable driver blocklist.

The preview is a non-security update that is available for Windows 10 and Windows 11 22H2. It contains all the changes in the upcoming November Patch Tuesday, except security patches.

However, this preview also includes Microsoft’s answer to a serious security-related error that the company made with its Windows kernel vulnerable driver blocklist – an optional security hardening capability introduced in Windows 10, version 1809 that’s on by default in Windows 11 22H2.

Also: Why can’t I get Windows 11 22H2 yet?

As ArsTechnica reported earlier this month, researchers recently discovered that Microsoft was failing to update the vulnerable driver blocklist with new instances of attacks that used correctly signed but vulnerable third-party drivers (for things like printers, motherboards and other hardware). Sophisticated attackers like vulnerable drivers because they’re properly signed by vendors and have privileged access to the Windows kernel.   

Microsoft first tackled this signed-but-vulnerable driver attack in its SecureCore PCs released in 2020 in response to a rise in state-sponsored and criminal attacks using vulnerabilities in drivers. In 2021, Microsoft said it had identified 50 vendors that had released many ‘wormhole’ drivers amenable to this type of attack.

Secured-Core PCs shipped with Hypervisor-Protected Code Integrity (HVCI) on by default to block these drivers from loading, but HVCI had to be enabled for Windows 10, version 1809 and later for the vulnerable driver blocklist to be enabled. In Windows 11 22H2, the blocklist is enabled by default on all devices, not just Secured-Core ones.

In October, Will Dormann, a well-known vulnerability analyst, flagged that a newly added driver on the blocklist was loading on his HVCI-enabled system. Because of this, he doubted the veracity of Microsoft’s claims in its documentation for the feature. 

Microsoft has now explained that the failed updates to the blocklist were down to it only updating for “full Windows OS releases”, although it’s not clear if this means previously installed Windows versus fresh installs, or just that older versions of Windows were stuck on a blocklist that couldn’t be updated.

“This October 2022 preview release addresses an issue that only updates the blocklist for full Windows OS releases. When you install this release, the blocklist on older OS versions will be the same as the blocklist on Windows 11, version 21H2 and later,” Microsoft states in a support page detailing “the vulnerable driver blocklist after the October 2022 preview release.”

Microsoft had told Ars Technica that it was in fact regularly updating the vulnerable driver list, but that there was “a gap in synchronization across OS versions.” 

So, the October 2022 preview release is the promised fix, which should be released broadly in the November 2022 Patch Tuesday through Windows Update. 

Microsoft’s release notes for the October Windows 11 22H2 preview update states: “It updates the Windows kernel vulnerable driver blocklist that is in the DriverSiPolicy.p7b file. This update also ensures that the blocklist is the same across Windows 10 and Windows 11. For more information, see KB5020779.”

Taskbar changes

Otherwise, this update changes the look of the taskbar in a way that should improve discoverability, although this is only available to a small audience at the moment. Microsoft doesn’t say what the visual changes are, but points to its search box in the taskbar. 

Also, in coming weeks, all users will be able to right-click the taskbar to reveal Task Manager in the context menu.

Microsoft is adding a new consent form for users enrolled in Windows Hello Face and Fingerprint. “You have new choices for your biometric data,” Microsoft notes in the Message center entry for this update.

For a refresh on Microsoft’s monthly quality updates, this one is the ‘C’ release that includes non-security changes and improvements and is released ahead of the following month’s Patch Tuesday update (the ‘B’ release).

Also: The 10 best Windows laptops: Top notebooks, 2-in-1s, and ultraportables 

This update also employs visual changes designed to enhance the backup experience when using a Microsoft Account. And users will be able to manage OneDrive subscriptions and related storage alerts through the Settings app when signed in with a Microsoft Account. 

For enterprise users, there are several fixes coming for Microsoft Edge IE mode, the feature Microsoft offers for legacy business apps that rely on IE. It resolves an issue where Edge IE mode wouldn’t open web pages when Windows Defender Application Guard (WDAG) is enabled but Network Isolation policies have not been configured. 




Related

ShareTweetShare

Related Posts

A live blog of TikTok CEO Shou Zi Chew's testimony before Congress, as he attempts to address national security concerns over ByteDance's ownership of the app (Washington Post)- Dejkala
Latest update

A live blog of TikTok CEO Shou Zi Chew's testimony before Congress, as he attempts to address national security concerns over ByteDance's ownership of the app (Washington Post)- Dejkala

March 23, 2023
Congress proposes 2 bills to ban TikTok. Here’s what they mean- Dejkala
Latest update

Congress proposes 2 bills to ban TikTok. Here’s what they mean- Dejkala

March 23, 2023
Epic’s new motion-capture animation tech has to be seen to be believed- Dejkala
Latest update

Epic’s new motion-capture animation tech has to be seen to be believed- Dejkala

March 23, 2023
‘Star Trek: Picard’ thinks the kids aren’t alright- Dejkala
Latest update

‘Star Trek: Picard’ thinks the kids aren’t alright- Dejkala

March 23, 2023
Relativity Space has a successful failure with the debut of Terran 1- Dejkala
Latest update

Relativity Space has a successful failure with the debut of Terran 1- Dejkala

March 23, 2023
Lenovo LOQ laptops, desktop woo PC gamers on a budget- Dejkala
Latest update

Lenovo LOQ laptops, desktop woo PC gamers on a budget- Dejkala

March 23, 2023
Next Post
South Korean prosecutors indict four current and former Samsung employees over allegedly stealing and leaking semiconductor tech to overseas companies (Yonhap News Agency)- Dejkala

South Korean prosecutors indict four current and former Samsung employees over allegedly stealing and leaking semiconductor tech to overseas companies (Yonhap News Agency)- Dejkala

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Categories

  • Earn Money Online
  • Game news and review
  • Laptops
  • Latest update
  • Smartphone Reviews & News
  • TODAY Tech News
  • Upcoming Technology
  • Wordpress plugin
  • WordPress themes
  • World Wide Bike Reviews and News
  • World Wide Car News

Recommended

The Balolo Tripod Stand takes Apple’s HomePod Mini to the next level. Literally- Dejkala

The Balolo Tripod Stand takes Apple’s HomePod Mini to the next level. Literally- Dejkala

January 12, 2023
Noah Perlman, the former chief operating officer at Gemini Trust, joined Binance in January 2023 as its chief compliance officer (Olga Kharif/Bloomberg)- Dejkala

Noah Perlman, the former chief operating officer at Gemini Trust, joined Binance in January 2023 as its chief compliance officer (Olga Kharif/Bloomberg)- Dejkala

February 14, 2023
Cyber Monday laptop deal: Save $450 on this 13-inch Samsung Galaxy Book2 360- Dejkala

Cyber Monday laptop deal: Save $450 on this 13-inch Samsung Galaxy Book2 360- Dejkala

November 28, 2022
Source: Apple is working on an iPad with a 16-inch screen, the largest iPad yet and in line with the company's largest laptop, and is planning a Q4 2023 release (Wayne Ma/The Information)- Dejkala

Source: Apple is working on an iPad with a 16-inch screen, the largest iPad yet and in line with the company's largest laptop, and is planning a Q4 2023 release (Wayne Ma/The Information)- Dejkala

October 26, 2022
WhatsApp launches ‘Code Verify’ feature to increase user protection

1 device will run on 4 devices, stable with multi-device feature

March 22, 2022
Despite climate pledges by US tech giants, Greenpeace finds key supplies for Amazon, Microsoft, Google, HP, and others remain deeply reliant on fossil fuels (Bloomberg)- Dejkala

Despite climate pledges by US tech giants, Greenpeace finds key supplies for Amazon, Microsoft, Google, HP, and others remain deeply reliant on fossil fuels (Bloomberg)- Dejkala

October 28, 2022
A live blog of TikTok CEO Shou Zi Chew's testimony before Congress, as he attempts to address national security concerns over ByteDance's ownership of the app (Washington Post)- Dejkala

A live blog of TikTok CEO Shou Zi Chew's testimony before Congress, as he attempts to address national security concerns over ByteDance's ownership of the app (Washington Post)- Dejkala

March 23, 2023
Congress proposes 2 bills to ban TikTok. Here’s what they mean- Dejkala

Congress proposes 2 bills to ban TikTok. Here’s what they mean- Dejkala

March 23, 2023
Epic’s new motion-capture animation tech has to be seen to be believed- Dejkala

Epic’s new motion-capture animation tech has to be seen to be believed- Dejkala

March 23, 2023

Categories

  • Earn Money Online
  • Game news and review
  • Laptops
  • Latest update
  • Smartphone Reviews & News
  • TODAY Tech News
  • Upcoming Technology
  • Wordpress plugin
  • WordPress themes
  • World Wide Bike Reviews and News
  • World Wide Car News

Pages

  • About Us
  • Banking & loan
  • Car’s & Bike’s
  • Contact Us
  • Games
  • Home
  • Home 2
  • Privacy Policy
  • Tech

© 2022 Dejkala

No Result
View All Result
  • Homepages
    • Home – Layout 1
    • Home – Layout 2

© 2022 Dejkala