25 ms·
Microsoft did break backwards compatibility with some drivers (packed stuff that relied on being able to write to executable sections, for instance) w/ HVCI and
by not_a9 1mo ago
Microsoft did break backwards compatibility with some drivers (packed stuff that relied on being able to write to executable sections, for instance) w/ HVCI and then with some other stuff (for instance, drivers using push+ret for obfuscating function calls + some exception handling related machinery some virtualization based obfuscators used) with KCET.
With that being said virtualization based security is not mandatory, though compliance is needed for signing new drivers (note: this is funky too and some drivers will do HVCI-noncompliant things when it’s disabled, like some anticheat drivers hooking #PF to more efficiently catch unsigned code execution in HVCI-free scenario). I think next backwards compatibility breaking move will be enabling SMAP.