Monitor this situation.
Unsubscribe anytime.
[SITUATION] · [QUIET] · [TECHNOLOGY]
2 clusters · 3 sources · 10 days · First seen · Last updated
Security software privilege escalation vulnerabilities
Overview
Researchers have identified methods to exploit security software for privilege escalation and system neutralization.
Initial findings from Check Point Research highlighted that the Microsoft Defender Boot-Time Removal (BTR.sys) driver could be weaponized. By repurposing this trusted, Microsoft-signed driver, attackers with administrative privileges could perform kernel-level operations, such as deleting files or modifying registry keys, to effectively neutralize antivirus protections.
Subsequent reports expanded on these risks, identifying vulnerabilities in both Kaspersky Endpoint Security and Microsoft Defender. A researcher claimed a zero-day vulnerability in Kaspersky that could allow local users to gain unauthorized permissions. Additionally, a new exploit named ‘ShieldBreak’ (CVE-2026-69414) was identified, which bypasses previous patches to use the Cloud Filter API and CLFS log manipulation to grant attackers SYSTEM-level access via Microsoft Defender.
Entities
Microsoft · Kaspersky · Check Point Research · Windows 11 · Microsoft Defender
Timeline
-
17 days ago
[TECHNOLOGY] 3 sourcesCybersecurity researchers identify privilege escalation flaws in Kaspersky and Microsoft DefenderResearchers have identified new privilege escalation vulnerabilities affecting Kaspersky Endpoint Security and Microsoft Windows Defender, potentially allowing local users to gain elevated system permissions.
-
27 days ago
[TECHNOLOGY] 2 sourcesMicrosoft Defender driver can be weaponized to disable securityCheck Point Research found that Microsoft Defender’s BTR.sys driver can be repurposed to perform privileged kernel-level operations, potentially allowing attackers to disable security protections.
Sources
cybernoz.com · invitehealth.substack.com · saferworld.org.uk