Microsoft Defender Driver Can Be Weaponized to Disable EDR and AV From Windows Kernel
Researchers found that a real Microsoft security tool built into Windows can be misused by someone who already has high-level access to a computer to turn off or weaken other protection tools. This is not a flaw that spreads by itself, but it could help an attacker stay hidden after breaking into a Windows device.
Who is at risk
People and organizations using Windows computers are most at risk if someone else may already have administrator-level access to their device.
What to watch for
Watch for security tools suddenly turning off, missing protection alerts, unexpected requests for administrator approval, or other unusual system changes on a Windows computer.
What to do
Make sure Windows and security software are fully updated, limit administrator access, and have a trusted IT professional check any device where protections unexpectedly stop working.
