Black Hat: Windows 10 Credential Guard at Risk | eWeek

Windows 10 Credential Guard Risk Exposed at Black Hat

Windows 10 Credential Guard Risk Exposed at Black Hat
Aug 3, 2016
1 minute read
eWeek content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

LAS VEGAS–Microsoft’s Windows 10 includes many innovative security features that are intended to help minimize risk and improve user experience. One such feature is Credential Guard, which aims to protect users against attacks. However, according to security firm Bromium, many risks remain.

In a video interview with eWEEK ahead of a session on Aug. 4 at the Black Hat USA conference here, Rahul Kashyap, chief security architect and executive vice president at security firm Bromium, discussed multiple flaws his firm found in Windows 10, including Credential Guard as well the kernel code integrity feature.

Kashyap explained that Credential Guard is an effort from Microsoft to limit or eliminate the risk of an attack known as “Pass-the-Hash,” where an attacker is able to access a password or credential hash and then reuse it in an attack. Credential Guard makes use of Windows 10 integrated virtualization, which Kashyap said is a step forward for security, but is still lacking in some security controls.

Bromium has alerted Microsoft to the issues it found, and some, but not all, the identified risks have been patched.

“The Credential Guard issue is tricky and will be difficult to fix,” Kashyap said.

Watch the full video interview with Kashyap below to get the details on the flaws:


Sean Michael Kerner is a senior editor at eWEEK and InternetNews.com. Follow him on Twitter @TechJournalist.

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.