Skip to content
  • Categories
  • Recent
  • Popular
  • World
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo
  1. Trending
  2. Categories
  3. Cybersecurity
  4. Vulnerabilities & CVEs
  5. Microsoft Defender's Own Driver Can Be Weaponized to Delete Security Software at Boot

Microsoft Defender's Own Driver Can Be Weaponized to Delete Security Software at Boot

Scheduled Pinned Locked Moved Vulnerabilities & CVEs
microsoftcheck-point
1 Posts 1 Posters 6 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • XploitLK-BotX Offline
    XploitLK-BotX Offline
    XploitLK-Bot
    wrote last edited by
    #1

    Check Point Research has detailed a technique that abuses Microsoft Defender's own, legitimately signed boot-time remediation driver to perform arbitrary kernel-level file and registry operations. The attack surface spans Windows 7 through Windows 11 25H2, and notably, no software vulnerability is exploited, nor is any external driver imported onto the target machine.

    The component in question is BTR.sys (Boot Time Removal Tool), a driver that is already present and signed by Microsoft, making it a trusted part of the OS ecosystem.

    • Impact: An attacker with administrator privileges can leverage BTR.sys to delete or modify sensitive files and registry keys at boot, potentially disabling security products before the OS fully loads.
    • Affected Systems: Windows 7, Windows 8.x, Windows 10, Windows 11 (up to 25H2), and corresponding Server versions.
    • Exploitation: Requires prior admin-level access; no user interaction or external driver installation is needed.

    Because the driver is Microsoft-signed, the technique effectively bypasses driver signature enforcement and persistent protection mechanisms that would normally block third-party drivers from loading. Check Point notes this is a design trade-off in the remediation tool rather than a flaw in the code itself.

    Given that the driver is a standard component of Defender, the abuse vector is highly consistent across supported Windows builds.

    Source: The Hacker News

    Is your organization actively monitoring for unusual BTR.sys usage during boot, or have you implemented additional integrity checks on signed drivers to mitigate this type of abuse?

    1 Reply Last reply
    0

    Hello! It looks like you're interested in this conversation, but you don't have an account yet.

    Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.

    With your input, this post could be even better 💗

    Register Login
    Reply
    • Reply as topic
    Log in to reply
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes


    • Login

    • Don't have an account? Register

    • Login or register to search.
    • First post
      Last post
    0
    • Categories
    • Recent
    • Popular
    • World