- Microsoft's vulnerable driver block list protects the system kernel by preventing the loading of drivers dangerous identified as potentially exploitable.
- The blocklist is maintained and updated in collaboration with manufacturers, integrating into technologies such as Windows Defender, App Control and ASR rules to minimize risks.
- You can enable, disable, or customize the blocking policy in both home and business environments, adjusting the level of protection according to your needs.
In the world of cybersecurity , protecting the Windows operating system kernel is a top priority for both home users and businesses. Over the years, Microsoft has implemented increasingly sophisticated mechanisms to shield the kernel from threats, but attackers continue to seek ways to execute privileged code. One of the most dangerous—and increasingly common—methods is to exploit vulnerabilities in the drivers loaded onto the system. Many of these drivers are legitimate and digitally signed, but they contain security flaws that can be exploited.
To address this reality, Microsoft has developed the Vulnerable Driver Blocklist, which aims to prevent the execution of dangerous drivers in the Windows kernel. This feature, increasingly prevalent and enabled by default in the latest versions of the operating system, is a key component of the protection ecosystem that includes Windows Defender and other advanced security policies.
What is the Microsoft Vulnerable Driver Blocklist?
The Microsoft Vulnerable Driver Block List is a defense mechanism designed to prevent certain drivers, identified as potentially unsafe or directly dangerous to system integrity, from running on the Windows kernel. These drivers, although usually properly signed and distributed by legitimate manufacturers, have at some point exhibited vulnerabilities that can be exploited by malicious software to gain elevated privileges, bypass security systems, or compromise the normal operation of the machine.
Microsoft maintains and updates this list in collaboration with hardware manufacturers (IHVs and OEMs) and the security community, ensuring it always includes drivers whose exploitation poses a real threat. Its primary function is to automatically block the execution of these drivers to prevent privilege escalation, the introduction of rootkits, or the manipulation of antimalware tools.

Why is a driver blocklist necessary?
For some time now, attackers have known that it's not always necessary to develop malware from scratch to gain low-level system control. The technique known as Bring Your Own Vulnerable Driver (BYOVD) exploits the existence of legitimate drivers with security flaws to deploy advanced threats . Cybercriminals can install and load a vulnerable driver (often old but still signed) and then exploit it to gain access to internal operating system resources, disable antivirus software, extract credentials, or install rootkits.
These maneuvers have even been seen in ransomware operations and targeted attacks against large corporations. Microsoft has detected the systematic use of this technique by both advanced threat actors and basic malware developers , highlighting the need for a mechanism to control and limit which drivers can run in the system's most critical environment.
Collaboration between Microsoft and manufacturers to identify dangerous drivers
One of the strongest aspects of Microsoft's defense lies in its direct collaboration with major hardware manufacturers and independent software vendors. Whenever a driver vulnerability is discovered, Microsoft works with the manufacturer to be notified as soon as possible, add the driver to the blocked list if necessary, and coordinate the release of an update or patch to resolve the issue . This allows them to protect users by preventing the vulnerable driver from being executed, and also ensures that the corrected versions are safely distributed throughout the Windows ecosystem.
Developers and manufacturers can submit suspicious drivers directly to Microsoft for security analysis, or request revisions and changes if a driver has been patched after an update. The company offers dedicated resources and channels for reporting issues, which speeds up the detection and rapid addition of new drivers to the list.
What types of drivers crash?
Microsoft's policy for defining which drivers should be included in this list is based on detecting those that meet at least one of the following criteria:
- They present known security vulnerabilities which can be exploited to elevate privileges or compromise the integrity of the Windows kernel.
- They exhibit malicious behavior, such as having been used to distribute malware, rootkits or harmful software.
- They include digital signature certificates used to sign malware or tools of hacking.
- They have practices that evade the Windows security model, although not strictly malicious, can be exploited by attackers to gain excessive control over the system.
Thanks to this approach, the list not only protects against active vulnerabilities, but also against the entire chain of attacks based on outdated or inadequately protected drivers . The presence of a driver on the list means that the operating system will block its loading and execution, thus preventing malware from exploiting it.
Blocklist Evolution: Integration and Updates
Microsoft's vulnerable driver blocklist has been progressively integrated into all modern versions of Windows. Starting with Windows 10 version 1809, it was initially an optional feature for users and environments that enabled advanced technologies such as Hypervisor Protected Code Integrity (HVCI) or S-mode. However, with the release of Windows 11 , and especially with the 22H2 update, it has been enabled by default on all compatible devices.
This means that all users of Windows 11 22H2 (and later versions) have blocklist protection automatically enabled, without any additional configuration . For earlier versions or Windows 10, activation of the blocklist depends on the corresponding security feature being enabled, such as Smart App Control, S mode, or HVCI, although it can also be added manually through optional Windows Updates.

How often is the blocklist updated and how are new features distributed?
Microsoft updates the driver blocklist with each major new version of Windows , typically once or twice a year, but may also deploy additional updates through standard operating system maintenance. The latest versions of the blocklist are distributed simultaneously as optional Windows Updates for Windows 10 users (starting with version 20H2) and Windows 11 users (21H2 and later).
However, if an administrator wants to ensure they are always protected with the latest version of the blocklist, they can use tools like App Control for Business , which allows them to apply the updated list of blocked drivers even before it arrives via a standard update. Microsoft also publishes manual downloads of the updated file, along with detailed instructions for its implementation.
How user protection works: Integration with Windows Defender and App Control
The blocklist integrates its functionality with other Windows security measures, particularly Windows Defender and App Control. In the case of Defender, the system performs a thorough check on drivers that are being installed, assesses their presence on the blocklist, and, if warranted, blocks their execution and displays alerts in the Windows Security Center.
App Control for Business allows administrators to enforce the Microsoft blocklist using security policy directives . While it's an advanced option geared toward enterprise and professional environments, it's very useful for maintaining consistent security across the entire IT infrastructure. In fact, if it's not possible to enable certain features like S-mode or HVCI, Microsoft specifically recommends blocking the list of potentially dangerous drivers using App Control , although it advises testing the policy in audit mode first to avoid incompatibilities or accidentally blocking critical devices.
Step by step: How to manually download and apply the block list
For users or administrators who want to ensure they have the most up-to-date version of the blocklist file, Microsoft offers a manual procedure. The process typically involves downloading the App Control Policy Update Tool, obtaining the blocklist binaries, renaming the policy file to SiPolicy.p7b , copying it to the %windir%\system32\CodeIntegrity directory , and running the update to activate the new policy. This will automatically stop any attempt to load a driver listed as vulnerable.
To verify that the policy is operational, simply open the Event Viewer, go to the Microsoft – Windows – CodeIntegrity – Operational log and filter by event ID 3099. There you can check the details of the applied policy and verify that it corresponds to the latest version.
Can blocking drivers cause compatibility issues?
One of the most frequently asked questions about this security feature is whether it could block necessary drivers and cause system failures. The answer is that, although the list has been carefully compiled to minimize conflicts, there is a possibility that, in very specific cases, blocking a driver could cause certain hardware or software to malfunction , or even result in a blue screen of death ( BSOD ).
Therefore, Microsoft recommends that system administrators apply and test the policy, especially in audit mode, before fully enabling it, reviewing blocking events to rule out interference with essential work components.
How to enable or disable the block list from Windows Security
In the latest versions of the operating system, managing this feature is easier than ever. Simply open the Windows Security app, navigate to "Device Security," and access the "Kernel Isolation" section.
There, the user will see the option to enable or disable Microsoft's vulnerable driver block list . Simply change the status according to your preference and restart your device for the changes to take effect. This process is identical in Windows 11 22H2 and later; in earlier versions, it may be necessary to additionally enable the Memory Integrity or HVCI feature to activate the protection.
Link to Attack Surface Reduction (ASR)
Kernel defense is not only based on the driver blocklist, but is part of a broader framework called Attack Surface Reduction (ASR) , which encompasses a set of rules designed to minimize opportunities for exploitation by malware and hackers. One of the most recommended ASR rules, and one that is enabled by default in many environments, is precisely the one that blocks the abuse of vulnerable signed drivers.
The ASR rules system is integrated into Microsoft Defender for Endpoint and allows you to set policies to block, audit, or warn end users. Each rule has its own unique identifier (GUID) and can be configured individually from the admin center or using tools like PowerShell.
List of ASR rules related to drivers and other common risks
In addition to the rule blocking vulnerable drivers, the ASR rule package includes many other measures relevant to corporate and personal security:
- Prevent Adobe Reader from creating child processes.
- Prevent Office applications from creating child processes or injecting code into other processes.
- Block the execution of potentially obfuscated scripts.
- Prevent JavaScript or VBScript from launching downloaded executable content.
- Block unsigned processes from units USB or copied/impersonated system tools.
- Block the creation of dangerous WebShells or API calls from Office macros.
- Using advanced protections against ransomware and other sophisticated attacks.
For each rule, you can specify whether it should be in blocking, audit, or warning mode, allowing it to adapt to the needs of each organization . This flexibility is key to maintaining security without sacrificing compatibility or daily workflow.
How are ASR rules applied and managed?
ASR rules can be applied through different mechanisms:
- From the console Microsoft Defender for Endpoints, setting policies at the company, group, or device level.
- Using Microsoft Intune, which allows centralized management of all rules and their distribution by profiles.
- Locally, using PowerShell to activate or audit a specific rule on a computer.
Each rule is identified by a unique GUID, and state combinations can be set:
unconfigured, blocked, audit or warning. Warning mode is especially useful in environments where you want to inform the user of the risk without automatically blocking the action, allowing them to make a decision under warning.
Passionate writer about the world of bytes and technology in general. I love sharing my knowledge through writing, and that's what I'll do on this blog, show you all the most interesting things about gadgets, software, hardware, tech trends, and more. My goal is to help you navigate the digital world in a simple and entertaining way.