Windows is finally fixing a years-old security hole in April
… If all drivers loaded during the evaluation period are trusted by the kernel policy, the system activates and enforces the new kernel trust policy. Enforced systems are now protected against untrusted drivers from the cross-signed program, not on the kernel trust policy. …