來源較早收集於 22m

Windows 封鎖舊版核心驅動程式

Windows 封鎖舊版核心驅動程式
PostLinkedIn
🖥️閱讀原文: Computerworld
#kernel-drivers#legacy-hardware#security-holemicrosoft-windowsmicrosoftwindows-11whcp

💡Windows 封鎖舊驅動:AI 開發者檢查硬體相容性,避免 2026 中斷

⚡ 30 秒速覽

有什麼變化

針對已廢棄交叉簽署根程式的核心驅動程式移除信任

為什麼重要

此更新可能中斷使用舊版硬體的 AI 開發環境,迫使更新驅動程式。企業需評估相容性以避免部署延遲。提升 Windows 核心安全,有利於安全 AI 工作負載。

下一步行動

使用 sigverif.exe 檢查 Windows 核心驅動程式簽署,並更新非 WHCP 驅動至最新版。

誰應關注:Developers & AI Engineers

關鍵要點

  • 針對已廢棄交叉簽署根程式的核心驅動程式移除信任
  • 2026 年 4 月以評估模式於 Windows 11 24H2+ 及 Server 2025 推出
  • 評估期需 100 小時運行及 2-3 次開機,若無不信任驅動則啟用封鎖
  • 解決憑證盜竊及禁用防毒等濫用風險

🧠 深度解析

本篇為 AI 生成分析,非原文內容。

🔑 增強重點摘要

  • The policy specifically targets the 'Windows Hardware Compatibility Publisher' (WHCP) program, mandating that all kernel-mode drivers must be signed via the Microsoft-managed portal rather than relying on legacy third-party Certificate Authorities.
  • This initiative is part of Microsoft's broader 'Secure Kernel' strategy, which aims to mitigate Bring Your Own Vulnerable Driver (BYOVD) attacks where threat actors use legitimate but outdated, signed drivers to gain kernel-level privileges.
  • Microsoft is providing a specific 'Driver Blocklist' (DBL) mechanism that will be updated independently of the OS version, allowing for the dynamic addition of newly discovered vulnerable drivers without requiring a full Windows feature update.

🛠️ 技術深入

  • The enforcement mechanism relies on the Windows Code Integrity (CI) subsystem, which validates the signature chain of kernel-mode binaries during the boot process and at load time.
  • The 'Evaluation Mode' utilizes a telemetry-based heuristic: the system monitors for the presence of drivers signed by deprecated cross-signing certificates; if no such drivers are detected after the 100-hour threshold, the system automatically transitions to 'Enforcement Mode'.
  • The policy change specifically invalidates signatures generated by the 'Microsoft Code Verification Root' and associated cross-signing certificates that were historically used to allow third-party vendors to sign drivers without direct Microsoft submission.

🔮 前景展望基於引用來源的 AI 分析

Legacy industrial and specialized hardware will face significant operational disruptions.
Many legacy hardware devices rely on drivers signed with older certificates that cannot be re-signed by the original vendors, rendering them incompatible with updated Windows kernels.
The frequency of kernel-level rootkit attacks will decrease significantly.
By eliminating the trust in legacy, easily exploitable drivers, Microsoft effectively closes one of the most common vectors for persistent, high-privilege malware.

時間線

2019-07
Microsoft mandates that all new kernel-mode drivers must be submitted to the Windows Hardware Dev Center for signing.
2021-09
Microsoft introduces the initial version of the vulnerable driver blocklist to prevent known insecure drivers from loading.
2024-10
Windows 11 24H2 is released, laying the architectural foundation for stricter kernel-mode code integrity enforcement.
📰

AI 週報

閱讀本週精選 AI 大事摘要 →

👉相關動態

AI 策展新聞聚合。所有內容版權歸原始發布者所有。
原始來源: Computerworld

這是摘要,不是原文。去看原站,或訂閱每週簡報。

每週電子報

每週一封,可隨時退訂。