< Back to situations

Monitor this situation.

[SITUATION] · [QUIET] · [TECHNOLOGY]

2 clusters · 3 sources · 10 days · First seen · Last updated

Security software privilege escalation vulnerabilities

Overview

Researchers have identified methods to exploit security software for privilege escalation and system neutralization.

Initial findings from Check Point Research highlighted that the Microsoft Defender Boot-Time Removal (BTR.sys) driver could be weaponized. By repurposing this trusted, Microsoft-signed driver, attackers with administrative privileges could perform kernel-level operations, such as deleting files or modifying registry keys, to effectively neutralize antivirus protections.

Subsequent reports expanded on these risks, identifying vulnerabilities in both Kaspersky Endpoint Security and Microsoft Defender. A researcher claimed a zero-day vulnerability in Kaspersky that could allow local users to gain unauthorized permissions. Additionally, a new exploit named ‘ShieldBreak’ (CVE-2026-69414) was identified, which bypasses previous patches to use the Cloud Filter API and CLFS log manipulation to grant attackers SYSTEM-level access via Microsoft Defender.

Entities

Microsoft · Kaspersky · Check Point Research · Windows 11 · Microsoft Defender

Timeline

  1. 17 days ago

    [TECHNOLOGY] 3 sources
    Cybersecurity researchers identify privilege escalation flaws in Kaspersky and Microsoft Defender

    Researchers have identified new privilege escalation vulnerabilities affecting Kaspersky Endpoint Security and Microsoft Windows Defender, potentially allowing local users to gain elevated system permissions.

  2. 27 days ago

    [TECHNOLOGY] 2 sources
    Microsoft Defender driver can be weaponized to disable security

    Check Point Research found that Microsoft Defender’s BTR.sys driver can be repurposed to perform privileged kernel-level operations, potentially allowing attackers to disable security protections.

Sources

cybernoz.com · invitehealth.substack.com · saferworld.org.uk