微软宣布计划在Windows Server 2025中加入TPM硬件认证要求,以封闭长期被利用的KMS激活漏洞[1]。这一举措旨在通过将KMS与TPM硬件模块绑定,使模拟服务器无法绕过硬件验证,从根本上杜绝传统KMS破解方案的有效性[1]。
根据计划,微软将从2025年8月开始在Windows Server 2025上加入TPM提示,而真正的强制TPM证明将在下一代Windows Server正式版本中实施[1]。KMS激活工具源自微软的企业授权体系,但因验证机制不完整而被逆向破解,并被广泛用于破解Windows和Office[1]。这一漏洞已存在近20年,最早可追溯到Windows Vista和Windows Server 2008时代[1]。
TPM是由IBM、英特尔等公司于1999年通过TCPA组织发布的硬件安全标准[1]。由于TPM内保存的信息无法通过软件模拟,可作为硬件身份证明,微软期望通过这一方式有效阻止激活工具的滥用[1]。
Microsoft has announced plans to integrate Trusted Platform Module (TPM) hardware authentication into Windows Server 2025 to eliminate the widely-exploited KMS activation vulnerability.[1] The company will introduce TPM prompts starting in August 2025, with mandatory TPM verification to be implemented in the subsequent generation of Windows Server.[1]
The KMS activation system, which has been leveraged for nearly two decades to circumvent licensing requirements for Windows and Office products, originated from Microsoft's enterprise licensing framework but has been reverse-engineered due to incomplete verification mechanisms.[1] By binding KMS authentication to TPM hardware modules, Microsoft aims to prevent server emulation from bypassing hardware-level validation, rendering traditional KMS cracking methods ineffective.[1] TPM, a security standard developed by IBM, Intel, and other companies through the Trusted Computing Platform Alliance (TCPA) in 1999, stores credentials that cannot be replicated through software alone, effectively serving as a hardware-based identity verification system.[1]