SECURITY·중요도 8·2026. 08. 21.·The Hacker News
Microsoft Defender's Own Driver Can Be Weaponized to Delete Security Software at Boot
── KO ──────────────────
Microsoft Defender의 드라이버가 보안 소프트웨어 삭제에 악용될 수 있다는 연구 결과.
Check Point Research는 Microsoft Defender의 부팅 시간 수정 드라이버를 악용해 Windows 시스템에서 보안 소프트웨어를 삭제할 수 있는 기술을 공개했습니다. 이 방법은 외부 소프트웨어 결함을 이용하지 않고 Windows 7부터 11 25H2까지의 시스템에서 임의의 커널 수준 파일 및 레지스트리 작업을 수행할 수 있습니다. 드라이버 BTR.sys는 합법적으로 서명된 드라이버입니다.
── EN ──────────────────
Research reveals Microsoft Defender's driver can be exploited to delete security software.
Check Point Research disclosed a technique that exploits Microsoft Defender's legitimate boot-time remediation driver to delete security software on Windows systems. This method performs arbitrary kernel-level file and registry operations from Windows 7 to Windows 11 25H2 without exploiting external software flaws. The driver, BTR.sys, is signed legitimately.