CyberSecurity News
Microsoft Defender's Own Driver Can Be Weaponized to Delete Security Software at Boot
AI summary
Researchers at Check Point have found a way to utilize a legitimate Microsoft Defender driver to carry out unauthorized actions on Windows systems. This technique affects Windows versions from 7 to 11, specifically 25H2, and does not rely on exploiting any software vulnerabilities or importing external drivers. The driver in question, known as the Boot Time Removal Tool, is a legitimate component of Microsoft Defender. It can be used to perform arbitrary kernel-level operations, including file and registry modifications, at boot time. This could potentially be used to delete security software. The driver's legitimacy and native presence on the system make it a significant concern.
This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.

