Windows Downgrade Attack Risks Exposing Patched Systems to Old Vulnerabilities
Briefly

CVE-2024-38202 allows an attacker to reintroduce mitigated vulnerabilities or circumvent VBS features by persuading users to perform system restores, while CVE-2024-21302 facilitates the replacement of current Windows files with outdated ones.
Alon Leviev's Windows Downdate tool exploits these vulnerabilities, potentially making patched Windows systems vulnerable to past flaws, rendering 'fully patched' systems meaningless across the Windows environment.
Read at The Hacker News
[
]
[
|
]