Saturday, April 27, 2024

Microsoft: disable memory integrity if something goes wrong – Naked Security

Related posts


Microsoft has finally clarified how users can fix a Windows security measure that is causing hardware problems: disable it. The advisory, released last week, is expected to relieve many users of Memory Integrity, a feature designed to protect Windows computers from misbehaving drivers.

Memory integrity is a feature inside a larger set of protections called Core Isolation. It uses hardware virtualization to protect sensitive processes from infection. These features are a subset of virtualization-based security features that Microsoft has offered to enterprise users since the delivery of Windows 10. It deployed Core Isolation and Memory Integrity in all editions of Windows in 2018.

Memory integrity (also known as hypervisor-protected code integrity or HVCI), uses Microsoft’s Hyper-V hypervisor to virtualize hardware that runs certain Windows kernel model processes, protecting them from malicious code injection .

One use case for Memory Integrity is to protect Windows from user mode drivers and misbehaving applications, possibly due to a exploited security breach. Hardware drivers are software developed by hardware vendors that allow devices to work with Windows. Even legitimate pilots can have bugs. An attacker could use these bugs to gain privileged access to the system. Memory integrity blocks sensitive kernel processes in this software.

When Microsoft first offered this feature as an upgrade, you had to activate it. In new installations of Windows, it was enabled by default.

This virtualization-based technology is great for protecting your system, but it is not without drawbacks. Users have complained that they are not compatible with different brands and versions of PCs and that they do not work with peripherals, including Microsoft’s own webcams.