Skip to content
OnMSFT.com
  • Home
  • About
  • Contact
  • Windows
  • Surface
  • Xbox
  • How-To
  • OnPodcast
  • Edge
  • Teams
  • Gaming
Menu
  • Home
  • About
  • Contact
  • Windows
  • Surface
  • Xbox
  • How-To
  • OnPodcast
  • Edge
  • Teams
  • Gaming
  1. Home
  2. News
  3. Microsoft addresses malicious exploitation of certified Windows drivers

Microsoft addresses malicious exploitation of certified Windows drivers

OnMSFT Staff OnMSFT Staff
July 12, 2023
1 min read

Yesterday, Microsoft published a security advisory, ADV230001, addressing a concerning issue related to numerous drivers certified by the Windows Hardware Developer Program. These drivers were found to be exploited maliciously in post-exploitation activities. The discovery of this problem was credited to the diligent researchers at Sophos, who promptly notified Microsoft in early February 2023. To further emphasize the severity of the situation, Microsoft disclosed that both Trend Micro and Cisco also submitted their reports, collectively identifying 133 unsafe drivers, including non-certified ones.

Upon conducting a subsequent investigation, Microsoft uncovered that several developer accounts associated with the Microsoft Partner Center (MPC) were involved in submitting these malicious drivers to obtain a Microsoft signature. Consequently, all of these accounts were swiftly suspended. In addition, Microsoft implemented additional measures, such as blocking detections (commencing with Microsoft Defender 1.391.3822.0), which protect against legitimately signed drivers exploited in post-exploit activities.

In their findings, Sophos revealed the existence of two types of malicious drivers employed in recent attacks. The first type is similar to the maliciously signed drivers discovered last year and falls under the “Endpoint protection killer.” The second type resembles a rootkit, designed to operate discreetly as an inconspicuous background task.

Fortunately, home users need only ensure their operating systems are kept up to date, as no other devices or services have been impacted by these issues except for Windows PCs. Consequently, Azure, Xbox, or Microsoft 365 users can rest assured that they have no cause for concern.

via NotebookCheck

Related

Share this article:
Previous Article Our outlook for Xbox in the second half of 2023 Next Article Microsoft says Chinese hackers breached email accounts of U.S. Government agencies

Related Articles

State of Decay 3 Playtests Confirmed With Mutated Zombies and Co-op

State of Decay 3 Playtests Confirmed With Mutated Zombies and Co-op

April 5, 2026
Starfield launches on PS5 with 4K visual mode, 60FPS performance option, DualSense features, and new DLC available at release for players

Starfield Launches on PS5 With Two Modes and Full DualSense Support

April 5, 2026

ASUS Accused of Failing to Fix Laptop After 10 RMAs, User Denied 11th Request

April 5, 2026

Leave a Comment Cancel reply

Your email address will not be published. Required fields are marked *

Recent Posts

  • State of Decay 3 Playtests Confirmed With Mutated Zombies and Co-op
  • Starfield Launches on PS5 With Two Modes and Full DualSense Support
  • ASUS Accused of Failing to Fix Laptop After 10 RMAs, User Denied 11th Request
  • New Rowhammer Attacks Turn NVIDIA GPUs Into a System-Level Security Risk
  • Titan Army U275M could push gaming monitors to 1060Hz with dual-mode display

Recent Comments

  1. XxRIVTYxX on Intel Says It Tried to Help Before Crimson Desert Dropped Arc Support
  2. Gaurav Kumar on Chrome Prepares Nudge to ‘Move Tabs to the Side’ as Vertical Tabs Near Release
OnMSFT.com

The Tech News Site

Categories

  • Windows
  • Surface
  • Xbox
  • How-To
  • OnPodcast
  • Gaming
  • Edge
  • Teams

Recent Posts

  • State of Decay 3 Playtests Confirmed With Mutated Zombies and Co-op
  • Starfield Launches on PS5 With Two Modes and Full DualSense Support
  • ASUS Accused of Failing to Fix Laptop After 10 RMAs, User Denied 11th Request
  • New Rowhammer Attacks Turn NVIDIA GPUs Into a System-Level Security Risk
  • Titan Army U275M could push gaming monitors to 1060Hz with dual-mode display

Quick Links

  • About OnMSFT.com
  • Contact OnMSFT
  • Join Our Team
  • Privacy Policy
© 2010–2026 OnMSFT.com LLC. All rights reserved.
About OnMSFT.comContact OnMSFTPrivacy Policy