Microsoft Defender Driver Weaponized to Disable Security Software

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Check Point Research disclosed a technique that abuses Microsoft Defender's own legitimately signed boot-time remediation driver to perform arbitrary kernel-level file and registry operations on Windows systems.
- The affected systems span Windows 7 through Windows 11 25H2, meaning the technique works across nearly the full range of currently supported Windows versions.
- Microsoft Defender's remediation driver is legitimately signed by Microsoft, allowing it to load at boot without triggering integrity checks that would flag an unsigned or malicious driver.
- The source notes no software vulnerability is exploited — the capability comes from how the driver is designed to function at boot time, making it usable as a delete-or-disable primitive against other security software.
- By operating at the kernel level during boot, the technique can neutralize competing or host-based security products before they initialize, effectively bypassing endpoint protection.
Why it matters: Endpoint security vendors rely on kernel-level drivers to load before malware, but Microsoft's own signed driver now doubles as a weapon an attacker can repurpose to disable that protection at boot — across Windows 7 through Windows 11 25H2, with no exploit required, turning a legitimate Microsoft component into a built-in evasion tool.
Ask SkimNews



