Interestana
Home/News/Microsoft Defender Driver Vulnerable to Boot-Time Deletion
The Hacker News3 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

Microsoft Defender Driver Vulnerable to Boot-Time Deletion

Microsoft Defender Driver Vulnerable to Boot-Time Deletion

Check Point Research has disclosed a critical security vulnerability that allows attackers to weaponize a legitimate driver within Microsoft Defender to uninstall security software during the Windows boot process. The technique exploits the BTR.sys (Boot Time Removal Tool) driver, which is signed by Microsoft and operates at the kernel level. This driver is designed to remove malicious software and registry entries before the operating system fully loads, ensuring a clean startup. However, researchers found that by manipulating specific registry keys and file paths, an attacker with administrative privileges can trick BTR.sys into deleting legitimate security applications, including Microsoft Defender itself, or other third-party security solutions.

The exploit targets Windows systems ranging from Windows 7 through Windows 11 25H2. Crucially, this method does not rely on exploiting a flaw within the BTR.sys driver itself, nor does it require the attacker to import any external, unsigned drivers onto the system. Instead, it leverages the driver's intended functionality in an unintended way. The attack chain involves an attacker first gaining administrative access to a target Windows machine. Once administrative privileges are secured, the attacker can then modify specific registry keys that BTR.sys monitors during its boot-time operation. By altering these registry entries to point to the installation directories or critical files of security software, the attacker can cause the BTR.sys driver to delete these components as part of its legitimate cleanup process.

Check Point Research demonstrated that this technique can effectively disable or remove security software before it has a chance to load and protect the system. This leaves the Windows machine vulnerable to further exploitation and malware infections. The researchers highlighted that the BTR.sys driver is a legitimate component of Microsoft Defender, meaning its presence and signature are trusted by the Windows operating system. This trust is what the attackers exploit. The vulnerability underscores a broader challenge in security software design: ensuring that legitimate administrative tools cannot be easily subverted for malicious purposes. The ability to perform arbitrary kernel-level file and registry operations, even when executed by a signed driver, presents a significant risk if that driver's actions can be maliciously redirected.

While the specific details of the registry manipulation and file path targeting were not fully disclosed by Check Point Research to prevent immediate widespread exploitation, the disclosure serves as a warning to security vendors and system administrators. The technique highlights the importance of robust access controls and the need for security software to have internal safeguards against being tampered with by its own administrative components. The researchers have provided their findings to Microsoft, and it is expected that the company will implement mitigations to prevent this specific exploitation vector. This discovery emphasizes the ongoing cat-and-mouse game between security researchers and attackers, where even trusted system components can become vectors for compromise.

Original source — read the full reporting at the publisher:

Read on The Hacker News

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next