Microsoft Defender's Legitimate Driver Abused for Kernel-Level File and Registry Operations
A technique has been disclosed that leverages Microsoft Defender's legitimately signed boot-time remediation driver, BTR.sys, to perform arbitrary kernel-level file and registry operations on Windows systems from Windows 7 to Windows 11 25H2. This method does not exploit any software flaw or require importing any external driver. The vulnerability allows for potential deletion of security software at boot time, posing a significant risk to system security. Organizations are advised to monitor their systems for unusual activity related to Microsoft Defender's driver operations and implement additional security measures to prevent potential misuse.