[CYBERDIGEST]
⊞ Dashboard ⚡ Intelligence 📝 Reports 📚 Global Threats 💻 Hack Lab 🗄️ Resources ⌬ 0xJerry's Lab
📡 RSS Feed
System Online

Tag

#Security Software Deletion

articleHIGH 8.0

Microsoft Defender's Legitimate Driver Abused for Kernel-Level File and Registry Operations

A technique has been disclosed that leverages Microsoft Defender's legitimately signed boot-time remediation driver, BTR.sys, to perform arbitrary kernel-level file and registry operations on Windows systems from Windows 7 to Windows 11 25H2. This method does not exploit any software flaw or require importing any external driver. The vulnerability allows for potential deletion of security software at boot time, posing a significant risk to system security. Organizations are advised to monitor their systems for unusual activity related to Microsoft Defender's driver operations and implement additional security measures to prevent potential misuse.

Aug 22, 20261 source