Microsoft Defender's Own Driver Can Be Weaponized to Delete Security Software at Boot

Summary

Check Point Research has revealed a method to weaponize Microsoft Defender's legitimate boot-time remediation driver, BTR.sys, to execute arbitrary kernel-level file and registry operations on Windows systems. This technique bypasses the need for external drivers or software flaws, allowing attackers to potentially disable security software during system startup.

IFF Assessment

FOE

This vulnerability allows attackers to disable security software, which is detrimental to defenders.

Severity

8.0 High (AI Estimated)

This vulnerability allows for local privilege escalation and the deletion of critical security files, leading to significant impact on confidentiality, integrity, and availability. The ease of execution and lack of external software requirement contribute to a high score.

Defender Context

Defenders need to be aware of this technique that leverages trusted system components for malicious purposes. This highlights the importance of monitoring for unusual kernel-level operations and ensuring robust endpoint detection and response (EDR) solutions are in place to detect and block such file manipulation attempts during boot.

Read Full Story →