Windows Update¤Ê¤é¤Ì¡ÖWindows Downdate¡×¤ò¹Ô¤¦¤³¤È¤Ç¡¢½¤ÀµºÑ¤ß¤Î¥Ð¥°¤ä¥»¥­¥å¥ê¥Æ¥£¥Û¡¼¥ë¤òÉü³è¤µ¤»¡¢´°Á´¤Ë¥¢¥Ã¥×¥Ç¡¼¥È¤µ¤ì¤¿¤Ï¤º¤Î¥·¥¹¥Æ¥à¤ò´ÝÍç¤Ë¤·¤Æ¤·¤Þ¤¦¡Ö¥À¥¦¥ó¥°¥ì¡¼¥É¹¶·â¡×¤¬¡¢¥»¥­¥å¥ê¥Æ¥£¸¦µæ¼Ô¤Ë¤è¤Ã¤Æȯɽ¤µ¤ì¤Þ¤·¤¿¡£Microsoft¤Ï¤³¤ÎÀȼå(¤¼¤¤¤¸¤ã¤¯)À­¤Ø¤ÎÂбþ¤òµÞ¤¤¤Ç¤¤¤Þ¤¹¤¬¡¢±Æ¶Á¤¬¹­ÈϤˤ錄¤ë¤¿¤á»þ´Ö¤¬¤«¤«¤ë¸«Ä̤·¤Ç¤¹¡£

Windows Downdate: Downgrade Attacks Using Windows Updates - Black Hat USA 2024 | Briefings Schedule

https://www.blackhat.com/us-24/briefings/schedule/index.html#windows-downdate-downgrade-attacks-using-windows-updates-38963

Windows Update downgrade attack "unpatches" fully-updated systems

https://www.bleepingcomputer.com/news/microsoft/windows-update-downgrade-attack-unpatches-fully-updated-systems/

¥»¥­¥å¥ê¥Æ¥£´ë¶È¡¦SafeBreach¤Î¸¦µæ¼Ô¤Ç¤¢¤ë¥¢¥í¥ó¡¦¥ì¥ô¥£¥¨¥Õ»á¤Ï¡¢2024ǯ8·î3Æü¤«¤é³«ºÅ¤µ¤ì¤Æ¤¤¤ë¥»¥­¥å¥ê¥Æ¥£¥«¥ó¥Õ¥¡¥ì¥ó¥¹¡ÖBlack Hat 2024¡×¤Ç¡¢Windows 10¡¢11¤ª¤è¤ÓWindows Server¤Ë¸ºß¤¹¤ë2¤Ä¤Î¥¼¥í¥Ç¥¤ÀȼåÀ­¤Ë¤è¤ê¡¢´°Á´¤Ë¥¢¥Ã¥×¥Ç¡¼¥È¤µ¤ì¤¿¥·¥¹¥Æ¥à¤Ë¸Å¤¤¥»¥­¥å¥ê¥Æ¥£¥Û¡¼¥ë¤òºÆƳÆþ¤Ç¤­¤ë¤³¤È¤òȯɽ¤·¤Þ¤·¤¿¡£

¤³¤Î¥À¥¦¥ó¥°¥ì¡¼¥É¹¶·â¤Ç¤Ï¡¢¶¼°Ò¥¢¥¯¥¿¡¼¤ÏºÇ¿·¤Î¥Ç¥Ð¥¤¥¹¤ò¸Å¤¤¥Ð¡¼¥¸¥ç¥ó¤Ë¶¯À©¥í¡¼¥ë¥Ð¥Ã¥¯¤µ¤»¡¢¥·¥¹¥Æ¥à¤òÍưפ˿¯³²¤Ç¤­¤ë¤è¤¦¤Ê¾õÂ֤ˤ·¤Æ¤·¤Þ¤¦¤³¤È¤¬¤Ç¤­¤Þ¤¹¡£

¥À¥¦¥ó¥°¥ì¡¼¥É¹¶·â¤¬È¯¸«¤µ¤ì¤¿¤­¤Ã¤«¤±¤Ï¡¢2023ǯ¤Ëȯ¸«¤µ¤ì¤¿¡ÖBlackLotus UEFI¥Ö¡¼¥È¥­¥Ã¥È¡×¤Ç¤¹¡£¤³¤Î¥Þ¥ë¥¦¥§¥¢¤Ï¡¢Windows¥Ö¡¼¥È¥Þ¥Í¡¼¥¸¥ã¡¼¤ò¥À¥¦¥ó¥°¥ì¡¼¥É¤·¤Æ¥»¥­¥å¥¢¥Ö¡¼¥È¤ò¥Ð¥¤¥Ñ¥¹¤¹¤ëµ¡Ç½¤ò»ý¤Ã¤Æ¤¤¤Þ¤·¤¿¡£

Windows 11¤ÎUEFI¥»¥­¥å¥¢¥Ö¡¼¥È¤ò¥Ð¥¤¥Ñ¥¹¤·¤ÆPC¤ò¾è¤Ã¼è¤ë¶²¤ë¤Ù¤­¥Þ¥ë¥¦¥§¥¢¡ÖBlackLotus¡×¤¬70Ëü±ß¼å¤ÇÈÎÇ䤵¤ì¤Æ¤¤¤ë¤³¤È¤¬È¯³Ð - GIGAZINE



Microsoft¤Ï´û¤ËBlackLotus UEFI¥Ö¡¼¥È¥­¥Ã¥È¤ËÂбþ¤·¤Æ¤¤¤Þ¤¹¤¬¡¢¡Ö¥À¥¦¥ó¥°¥ì¡¼¥É¹¶·â¤ÎɸŪ¤È¤Ê¤ë¤Î¤Ï¥»¥­¥å¥¢¥Ö¡¼¥È¤À¤±¤Ê¤Î¤À¤í¤¦¤«¡©¡×¤Èµ¿Ìä¤Ë»×¤Ã¤¿¥ì¥ô¥£¥¨¥Õ»á¤¬Windows Update¤òÄ´¤Ù¤¿¤È¤³¤í¡¢¹¹¿·¥×¥í¥»¥¹¤ò°­ÍѤ¹¤ë¤³¤È¤Ç¥À¥¤¥Ê¥ß¥Ã¥¯¡¦¥ê¥ó¥¯¡¦¥é¥¤¥Ö¥é¥ê(DLL)¤äNT¥«¡¼¥Í¥ë¤È¤¤¤Ã¤¿½ÅÍפÊOS¤Î¥³¥ó¥Ý¡¼¥Í¥ó¥È¤ò¥À¥¦¥ó¥°¥ì¡¼¥É¤Ç¤­¤ë¤³¤È¤¬È½ÌÀ¤·¤Þ¤·¤¿¡£

¤·¤«¤â¡¢¥À¥¦¥ó¥°¥ì¡¼¥É¹¶·â¤ò¤¹¤ë¤È½ÅÍפʥ³¥ó¥Ý¡¼¥Í¥ó¥È¤¬¤¹¤Ù¤Æ¸Å¤¤¥Ð¡¼¥¸¥ç¥ó¤Ë¥í¡¼¥ë¥Ð¥Ã¥¯¤µ¤ì¤Æ¤¤¤ë¤Ë¤â¤«¤«¤ï¤é¤º¡¢¹¹¿·¥Á¥§¥Ã¥¯¤Ç¤Ï´°Á´¤Ë¥¢¥Ã¥×¥Ç¡¼¥ÈºÑ¤ß¤È¤ß¤Ê¤µ¤ì¤ë¤Î¤Ç¡¢¥ê¥«¥Ð¥ê¥Ä¡¼¥ë¤ä¥¹¥­¥ã¥ó¥Ä¡¼¥ë¤ÇÌäÂê¤ò¸¡½Ð¤¹¤ë¤³¤È¤ÏÉÔ²Äǽ¤Ç¤·¤¿¡£

¤³¤Îȯ¸«¤Ë¤Ä¤¤¤Æ¥ì¥ô¥£¥¨¥Õ»á¤Ï¡¢¡Ö»ä¤Ï´°Á´¤Ë¥Ñ¥Ã¥Á¤¬Å¬ÍѤµ¤ì¤¿Windows¥Þ¥·¥ó¤ò¡¢²áµî¤Ë¸ºß¤·¤¿Ìµ¿ô¤ÎÀȼåÀ­¤ËÂФ·¤Æ̵ËÉÈ÷¤Ë¤¹¤ë¤³¤È¤¬¤Ç¤­¡¢½¤ÀµºÑ¤ß¤ÎÀȼåÀ­¤ò¥¼¥í¥Ç¥¤¤ËÊѤ¨¤Æ¡¢À¤³¦Ãæ¤Î¤¢¤é¤æ¤ëWindows¥Þ¥·¥ó¤Ç¡Ø´°Á´¤Ë¥Ñ¥Ã¥ÁŬÍѺѤߡ٤Ȥ¤¤¦ÍѸì¤ò̵°ÕÌ£¤Ê¤â¤Î¤Ë¤·¤Þ¤·¤¿¡×¤È¸ì¤Ã¤Æ¤¤¤Þ¤¹¡£



¥ì¥ô¥£¥¨¥Õ»á¤Ë¤è¤ë¤È¡¢²¾ÁÛ²½¥Ù¡¼¥¹¤Î¥»¥­¥å¥ê¥Æ¥£(VBS)¤ÎUEFI¥í¥Ã¥¯¤òʪÍýŪ¥¢¥¯¥»¥¹¤Ê¤·¤Ç¥Ð¥¤¥Ñ¥¹¤Ç¤­¤¿¤Î¤Ï¡¢¥ì¥ô¥£¥¨¥Õ»á¤¬ÃΤë¸Â¤ê¤³¤ì¤¬½é¤á¤Æ¤À¤È¤Î¤³¤È¡£¤Þ¤¿¡¢¤³¤ÎÌäÂê¤ÏMicrosoft¤À¤±¤Ç¤Ê¤¯¡¢¥À¥¦¥ó¥°¥ì¡¼¥É¹¶·â¤ò¼õ¤±¤ë²ÄǽÀ­¤Î¤¢¤ë¤¹¤Ù¤Æ¤ÎOS¥Ù¥ó¥À¡¼¤Ë¤È¤Ã¤Æ¤â±Æ¶Á¤¬Â礭¤¤¤â¤Î¤À¤È¥ì¥ô¥£¥¨¥Õ»á¤Ï»ØŦ¤·¤Æ¤¤¤Þ¤¹¡£

¥ì¥ô¥£¥¨¥Õ»á¤Ï¡¢ÀÕǤ¤¢¤ë¾ðÊ󳫼¨¥×¥í¥»¥¹¤Î°ì´Ä¤È¤·¤Æ¡¢2024ǯ2·î¤Ë¤³¤ÎÌäÂê¤òMicrosoft¤ËÊó¹ð¤·¡¢º£²ó¤ÎBlack Hat 2024¤Ç¤Îȯɽ¤Þ¤Ç¤Ë6¥«·î¤Îͱͽ´ü´Ö¤òÀߤ±¤Þ¤·¤¿¡£

¥À¥¦¥ó¥°¥ì¡¼¥É¹¶·â¤Î¸øɽ¤ÈƱ»þ¤Ë¡¢Microsoft¤Ï¤³¤ÎÉÔ¶ñ¹ç¤ò¡ÖWindows Update¥¹¥¿¥Ã¥¯¤Î¸¢¸Â¾º³Ê¤ÎÀȼåÀ­(CVE-2024-38202)¡×¤È¡¢¡ÖWindows¥»¥­¥å¥¢¥«¡¼¥Í¥ë¥â¡¼¥É¤Î¸¢¸Â¾º³Ê¤ÎÀȼåÀ­(CVE-2024-21302)¡×¤ÈǧÄꤷ¡¢¸ø³«¤·¤Þ¤·¤¿¡£

Microsoft¤Ë¤è¤ë¤È¡¢¤³¤ì¤Þ¤Ç¤Î¤È¤³¤í¤³¤ì¤é¤ÎÀȼåÀ­¤ò°­ÍѤ·¤è¤¦¤È¤¹¤ë»î¤ß¤ÏÆÃÄꤵ¤ì¤Æ¤¤¤Ê¤¤¤È¤Î¤³¤È¡£¤¿¤À¤·¡¢Microsoft¤Ï¸Å¤¤VBS¤Î¥·¥¹¥Æ¥à¥Õ¥¡¥¤¥ë¤ò̵¸ú²½¤¹¤ë¥¢¥Ã¥×¥Ç¡¼¥È¤Ë¼è¤êÁȤó¤Ç¤¤¤ëºÇÃæ¤Ç¤¢¤ê¡¢¤³¤ì¤¬´°Î»¤¹¤ë¤Þ¤ÇWindows¤Ï¥À¥¦¥ó¥°¥ì¡¼¥É¹¶·â¤ËÂФ·¤ÆÀȼå¤Ê¤Þ¤Þ¤È¤Ê¤ê¤Þ¤¹¡£

Microsoft¤Ï¡Ö¤³¤ÎÀȼåÀ­¤òÆÃÄꤷ¡¢¶¨Ä´Åª¤Ë³«¼¨¤¹¤ë¤³¤È¤ÇÀÕǤ¤ò»ý¤Ã¤¿Êó¹ð¤ò¤·¤Æ¤¯¤ì¤¿SafeBreach¤Î³èÆ°¤Ë´¶¼Õ¤·¤Æ¤¤¤Þ¤¹¡£Microsoft¤Ï¡¢Å°ÄìŪ¤ÊÄ´ºº¡¢±Æ¶Á¤ò¼õ¤±¤ë¤¹¤Ù¤Æ¤Î¥Ð¡¼¥¸¥ç¥ó¤Î¥¢¥Ã¥×¥Ç¡¼¥È¤Î³«È¯¡¢¸ß´¹À­¥Æ¥¹¥È¤ò´Þ¤àÊñ³çŪ¤Ê¥×¥í¥»¥¹¤ò¼Â»Ü¤·¡¢¤³¤Î¥ê¥¹¥¯¤«¤é¤ÎÊݸî¤òÄ󶡤¹¤ë¤¿¤á¤Î´ËϺö¤òÀѶËŪ¤Ë³«È¯¤·¤Æ¤¤¤Þ¤¹¡×¤È½Ò¤Ù¤Þ¤·¤¿¡£