logo

Researchers claim Windows Defender can be fooled into deleting databases

ID: 6b09c27a-057d-5320-aaac-001380d8a3f0

STIX ID: report--6b09c27a-057d-5320-aaac-001380d8a3f0

Feed Name: The Register (Security)

Threat Score
70/100

Date Published: 2024-04-22

Date Updated: 2026-04-26

Author: Laura Dobberstein

...
...

Researchers demonstrated that byte-signature detections in EDR products (Microsoft Defender and Kaspersky EDR) can be manipulated by embedding malware byte signatures into benign files (for example via user names, database entries, or comments) causing the EDR to falsely classify and delete those files. SafeBreach responsibly disclosed multiple bypasses to Microsoft (resulting in CVE-2023-24860 and CVE-2023-36010) and reported mitigations, while cautioning that such deletion vulnerabilities are hard to fully eliminate and can have severe irreversible impact if exploited at scale.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.