Windows Defender Driver Vulnerability Could Leave Systems Defenseless, Research Reveals
New research from Check Point Research (CPR) indicates that a Microsoft-signed Windows Defender remediation driver, specifically 'BTR.sys' (Boot-Time Removal driver), can be repurposed by attackers to compromise system security. The technique does not exploit a traditional vulnerability but rather abuses functionality intentionally built into the driver. CPR researcher Jiří Vinopal reverse-engineered the driver and its undocumented transaction format, discovering that BTR.sys can be instructed to perform arbitrary file and registry operations from kernel mode. This means that the driver, designed to remove malicious files and modify the registry, could be manipulated to delete legitimate files, alter critical system settings, and neutralize security controls, effectively leaving systems defenseless.