Compromised drivers put Windows 10 users at risk

DEF CON is the world’s longest running and largest underground hacking conference. During the latest conference, it was reported that all current versions of Windows 10 have serious issues with vulnerable drivers that could compromise systems.
Researchers from the firm Eclypsium found a flaw within the drivers for certain pieces of hardware. Their analysis found that the problem is widespread, affecting more than 40 drivers from at least 20 different vendors. All the drivers were certified by Microsoft and from trusted vendors such as Intel, AMD, Nvidia, and Realtek. The implications of this are serious as a flawed driver can compromise a machine and allow attackers to hack into a system, change privileges and add threats.
Eclypsium’s researchers stated, “drivers that provide access to system BIOS or system components for the purposes of updating firmware, running diagnostics, or customizing options on the component can allow attackers to turn the very tools used to manage a system into powerful threats that can escalate privileges and persist invisibly on the host.”
It was found that applications can be compromised so that they could be accessed and used by attackers acting as the user. Hackers could use accessible “low-privilege” applications to effect Windows operating systems, for example through Windows Kernel which is at the heart of Windows operating systems.
Microsoft have responded, “In order to exploit vulnerable drivers, an attacker would need to have already compromised the computer. To help mitigate this class of issues, Microsoft recommends that customers use Windows Defender Application Control to block known vulnerable software and drivers.”.
Some vendors, for example Intel, have already issued updates for the discussed drivers, whilst others are still to be released.
This news is another reinforcement for the practice of always keeping your Operating System and your machine’s devices/drivers up to date. The most concerning thing in this case is that the compromised drivers were certified (i.e. marked as safe) by Microsoft for global release and use.