Microsoft Defender's Boot-Time Driver Can Be Exploited for Malicious Use

A vulnerability in Microsoft Defender's boot-time driver allows attackers to delete security software at boot, potentially crippling Windows systems.

Bottom line: Security leaders must ensure their organizations' Windows systems are protected against this technique by disabling the boot-time driver and implementing robust security software updates.

What's happening: Researchers from Check Point Research have discovered a technique that exploits a legitimate Microsoft Defender boot-time driver to perform arbitrary kernel-level file and registry operations, affecting Windows 7 through Windows 11 25H2, and potentially impacting 180 million Windows users worldwide.

What to do: Security leaders should immediately disable the boot-time driver, update their security software to the latest version, and monitor their systems for any signs of malicious activity.

Source: The Hacker News