{"id":11683,"date":"2026-03-28T10:03:40","date_gmt":"2026-03-28T10:03:40","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/03\/28\/windows-11-and-server-2025-update-to-block-untrusted-cross-signed-kernel-drivers-by-default\/"},"modified":"2026-03-28T10:03:40","modified_gmt":"2026-03-28T10:03:40","slug":"windows-11-and-server-2025-update-to-block-untrusted-cross-signed-kernel-drivers-by-default","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/03\/28\/windows-11-and-server-2025-update-to-block-untrusted-cross-signed-kernel-drivers-by-default\/","title":{"rendered":"Windows 11 and Server 2025 Update to Block Untrusted Cross-Signed Kernel Drivers by Default"},"content":{"rendered":"<p>    Windows 11 and Server 2025 Update to Block Untrusted Cross-Signed Kernel Drivers by Default<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>Microsoft is taking a major step to harden the Windows operating system against kernel-level threats by removing trust for drivers signed by the deprecated <a href=\"https:\/\/cybersecuritynews.com\/lets-encrypt-unveils-new-generation-y-root\/\" target=\"_blank\" rel=\"noreferrer noopener\">cross-signed root program<\/a>.<\/p>\n<p>Starting with the April 2026 update, Windows 11 and Windows Server 2025 will block these untrusted drivers by default.<\/p>\n<p>This policy ensures that only drivers certified through the Windows Hardware Compatibility Program can load automatically, significantly reducing the attack surface for malicious actors.\u200b<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-closing-a-legacy-security-gap\"><strong>Closing a legacy Security Gap<\/strong><\/h2>\n<p>The cross-signed root program was introduced in the early 2000s to allow third-party certificate authorities to issue Windows-trusted code-signing certificates.<\/p>\n<p>However, this system provided no assurances regarding the security or compatibility of the kernel code. Because developers managed their own private keys, the program became a <a href=\"https:\/\/cybersecuritynews.com\/darkcloud-infostealer-emerges-as-major-threat\/\" target=\"_blank\" rel=\"noreferrer noopener\">frequent target for credential theft<\/a>, allowing threat actors to deploy rootkits.\u200b<\/p>\n<p>Microsoft officially deprecated this signing program in 2021, and all related certificates have since expired. Despite this, Windows continued to trust these legacy certificates to maintain compatibility with legacy hardware.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEinWAlInjWHf2GM65LtCVYzvGiTX7pW2PFVGHKivwTfXzN6oOpbOpbgalRaNZa4A1L3v_gDp197nlCfSRDuU6tCGbDCUOUyOldQVCDx_s-SO5lPYJcWalK6428OJ2odYuRHGAG4EUdeIng8M6rD1ExBO3tbELl5z9lgDhhy9unNyhV4RpAs72ukAXK9kkE\/s1600\/Screenshot%25202026-03-27%2520200901%2520%25281%2529.webp?ssl=1\" alt=\"Drivers will be blocked on enforced systems, with a notification displayed(source : microsoft)\"><figcaption class=\"wp-element-caption\">Drivers will be blocked on enforced systems, with a notification displayed(source: Microsoft)<\/figcaption><\/figure>\n<\/div>\n<p>This new update finally severs that lingering trust. Moving forward, the certification pipeline requires vendors to pass strict identity vetting, submit rigorous test results, and undergo malware scanning before receiving a protected Microsoft-owned certificate.<\/p>\n<p>To prevent system crashes, <a href=\"https:\/\/techcommunity.microsoft.com\/blog\/windows-itpro-blog\/advancing-windows-driver-security-removing-trust-for-the-cross-signed-driver-pro\/4504818\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Microsoft is introducing an explicit allow list <\/a>for highly reputable, widely used cross-signed drivers.<\/p>\n<p>The kernel update will also deploy in a careful evaluation mode. The <a href=\"https:\/\/cybersecuritynews.com\/windows-kernel-0%E2%80%91day-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">Windows kernel will audit driver load signals<\/a> to ensure the new policy will not disrupt critical functions.<\/p>\n<p>The system will only enforce the block after meeting specific runtime and restart thresholds.\u200b If an unsupported driver is detected during this audit phase, the system resets the evaluation timer and holds off on enforcement.\u200b<\/p>\n<p>Enterprise environments relying <span style=\"box-sizing: border-box; margin: 0px; padding: 0px;\">on<\/span>\u00a0internally<a href=\"https:\/\/cybersecuritynews.com\/linux-kernel-6-18-rc1-released\/\" target=\"_blank\" rel=\"noreferrer noopener\"> developed custom kernel drivers<\/a> have alternative options. Organizations can securely bypass the default block using an Application Control for Business policy.<\/p>\n<p>By signing this policy with an <a href=\"https:\/\/cybersecuritynews.com\/cisa-guidance-uefi-secure-boot\/\" target=\"_blank\" rel=\"noreferrer noopener\">authority rooted in the device\u2019s UEFI Secure Boot variables<\/a>, administrators can explicitly trust private signers.<\/p>\n<p>This ensures threat actors cannot arbitrarily load malicious drivers while legitimate internal operations continue uninterrupted.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong>Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>, <a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and <a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a> for daily cybersecurity updates. <a href=\"https:\/\/cybersecuritynews.com\/contact-us\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Contact us<\/a> to feature your stories.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/windows-11-and-server-2025-update\/\">Windows 11 and Server 2025 Update to Block Untrusted Cross-Signed Kernel Drivers by Default<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Abinaya<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/windows-11-and-server-2025-update\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Windows 11 and Server 2025 Update to Block Untrusted Cross-Signed Kernel Drivers by Default Microsoft is taking a major step to harden the Windows operating system against kernel-level threats by removing trust for drivers signed by the deprecated cross-signed root program. Starting with the April 2026 update, Windows 11 and Windows Server 2025 will block [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,2178,395],"tags":[130],"class_list":["post-11683","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-security-updates","category-windows","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/11683"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=11683"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/11683\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=11683"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=11683"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=11683"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}