UPDATE: Microsoft has tackled the crack and blacklisted the leaked OEM activation product key.

In less than a week since Windows 7 was released to manufacturing, the first crack for the Ultimate edition of the latest iteration of the Windows client is already available in the wild. The Windows 7 Build 6.1.7600.16385 Ultimate crack is capable of activating the high-end SKU of the operating system indefinitely. The product key comes from the only source possible, an OEM, as original equipment manufacturers are the first and for the time being the last group to receive the gold bits of the operating system from Microsoft. Together with the RTM development milestone of Windows 7, the Redmond company has also supplied OEM partners with activation product keys, one of which was extracted from a leaked OEM image of the platform.

Reports from various forums and websites (which I will not link to because they offer the proof-of-concept of the Windows 7 RTM Ultimate crack, along with the activation product key, which is illegal) indicate that the cracked client can bypass Windows genuine Advantage validation with no problems whatsoever. A Windows 7 Ultimate OEM DVD ISO from Lenovo has reportedly made the hack possible. Leaked on a Chinese forum, complete with the download links, the ISO allowed for hackers to grab the OEM-SLP (System-Locked Preinstallation) product key as well as the OEM certificate for Windows 7 RTM Ultimate via boot.wim.

The bypass designed for Windows 7 RTM involves abusing OEM activation 2.1, and in this regard the circumventing process is nothing more than an OEM hack. Via OEM activation 2.1, namely SLP 2.1, Microsoft allows OEMs to pre-activate Windows 7 for distribution preinstalled on new computers. In this context, the activation bypass process leading to the hacked Windows 7 RTM needs to be based on a BIOS (SLIC) hack first of all.

The procedure is by no means new. Hackers have managed to crack Windows Vista much in the same manner. In fact, the Windows 7 RTM Ultimate activation crack also relies on an OEM certificate from Windows Vista in order to function. At the time of this article hackers have made available in the wild SLIC 2.1 BIN harvested from computers on the market, as well as the genuine OEM certificate digitally signed by Microsoft, which automatically brings to the table the Private Key and the OEM Public Key as well as the OEMID (from SLIC in BIOS). Together with the leaked OEM SLP master product key Windows 7 can be hacked and the activation process bypassed. The result is a cracked copy of Windows 7 RTM Ultimate permanently activated.

It also seems that the crack is not limited to Lenovo machines. The activation process can also be circumvented on HP, Dell, and MSI computers according to reports. Because of the OEM product key, the crack is limited to the Ultimate edition of Windows 7 (useless for all other SKUs, Home Basic, Home Premium, Professional), but can be used on both 32-bit and 64-bit versions of the operating system.