A recent report by Check Point Research reveals a vulnerability in the Windows Defender Boot-Time Removal driver (BTR.sys), which can be exploited to bypass Endpoint Detection and Response (EDR) and Antivirus (AV) protections. The research highlights how BTR.sys, intended for defensive purposes, can be repurposed for offensive capabilities by executing arbitrary file and registry operations from Ring 0 without an actual exploit.
A proof-of-concept tool, BTR_CLI, was developed to demonstrate the driver’s capability to manipulate system files, including deleting crucial Defender binaries during the boot sequence. The findings indicate that this vulnerability requires pre-existing administrative rights and has not been observed in real-world attacks. Microsoft has stated that the issue does not warrant immediate attention as it relies on elevated privileges. Recommendations for mitigation include monitoring specific behaviors and restricting administrative privileges.