Microsoft hardens Vista against kernel-mode malware

eWeek | at | by Mike

With the threat from kernel-mode rootkits on the rise, Microsoft plans to make a significant policy change to block uncertified drivers from loading on x64 versions of Windows Vista.

Starting with Windows Vista and Windows Server, kernel-mode software must have a digital signature to load on x64-based computer systems.

The decision to block unsigned drivers from loading is a direct attempt to restrict the spread of powerful rootkits that intercept the native API in kernel-mode and directly manipulate Windows data structures.