Home > Common Problem > Microsoft introduces vulnerable driver blocklist in Windows Defender on Windows 10 and 11

Microsoft introduces vulnerable driver blocklist in Windows Defender on Windows 10 and 11

王林
Release: 2023-04-17 11:52:05
forward
9233 people have browsed it

Microsoft Windows Defender receives upgrades that will benefit Windows 10, Windows 11, and Windows Server 2016 or later. The Microsoft Vulnerable Driver Blocklist feature introduced into Defender will allow drivers with security vulnerabilities to be blocked from running on the device. David Weston, Microsoft's vice president of operating system security and enterprise, announced the update on March 27.

Microsoft introduces vulnerable driver blocklist in Windows Defender on Windows 10 and 11

Defender’s Microsoft Vulnerable Driver Blocklist feature is optional for users as it can be turned on and off, and it’s one for everyone Valuable tool as there are always security risks these days. Microsoft, on the other hand, says it will be enabled by default on certain devices, such as those running Windows 10 in S mode and those with Hypervisor Protection Code Integrity (HVCI) enabled.

For non-Windows 10 S mode devices, users can activate memory integrity prerequisites in several ways:

  • Start > Settings > Open the Settings app via the keyboard shortcut Windows-I program.
  • (Windows 10): Update & Security > Windows Security > Choose to turn on Windows Security
  • (Windows 11): Privacy & Security > Windows Security > Choose to turn on Windows Security
  • From the sidebar on the left, select Device Security.
  • Enable the "Core Isolation Details" link.
  • Enable block functionality by switching the Memory Integrity setting to On.
  • Restart the device you are using.

It will block drivers with specific characteristics that may pose a threat, such as malware or certificates used to sign malware. It will also block drivers with known security vulnerabilities and bypasses of the Windows security model, as cybercriminals can exploit them to escalate privileges in the Windows kernel.

The Driver Blocklist feature is based on a list of blocked drivers that Microsoft maintains with hardware vendors and OEMs. Nonetheless, after a suspect driver is submitted to Microsoft for analysis, manufacturers may require patching of issues in drivers included on the list.

The above is the detailed content of Microsoft introduces vulnerable driver blocklist in Windows Defender on Windows 10 and 11. For more information, please follow other related articles on the PHP Chinese website!

Related labels:
source:yundongfang.com
Statement of this Website
The content of this article is voluntarily contributed by netizens, and the copyright belongs to the original author. This site does not assume corresponding legal responsibility. If you find any content suspected of plagiarism or infringement, please contact admin@php.cn
Popular Tutorials
More>
Latest Downloads
More>
Web Effects
Website Source Code
Website Materials
Front End Template