A new tool called DefenderWrite exploits whitelisted Windows programs to bypass protections and write arbitrary files to antivirus executable folders, potentially allowing malware to persist.
See also: Notepad++: DLL Hijacking Vulnerability Allows Code Execution

Developed by cybersecurity expert Two Seven One Three, the tool introduces a new technique for penetration testers and red teams to drop payloads in highly protected locations without requiring kernel-level access.
This development highlights the ongoing challenges for virus self-protection mechanisms, where folders hosting AV executables are typically protected from modifications to prevent tampering.
By identifying system programs that antivirus vendors have whitelisted for updates and installations, attackers can exploit these exceptions to inject malicious DLLs, turning their own AV safeguards against them.
The release of the tool, shared via GitHub, has sparked discussions about the balance between functional needs for AV software and security risks in corporate environments.
The key innovation behind DefenderWrite lies in systematically scanning Windows executables to find those that have permission to access AV folders. By enumerating all .exe in directories like C:\Windows, it then uses process creation and remote DLL injection to test their ability to write to protected paths.
See also: RVTools site hacked and distributed Bumblebee malware

A custom DLL performs the file write operation and reports success or failure, allowing the tool to detect exploitable processes like msiexec.exe without triggering defenses. In testing on Windows 11 24H2 with Microsoft Defender version 4.18.25070.5-0, the method detected four such programs: msiexec.exe, Register-CimProvider.exe, svchost.exe , and lsass.exe.
This approach extends beyond Microsoft Defender. Similar whitelisting vulnerabilities have been confirmed in BitDefender, TrendMicro Antivirus Plus , and Avast, though specific details remain unknown to encourage independent verification.
DefenderWrite supports basic parameters for targeted operations, such as TargetExePath for the host executable, FullDLLPath for the injected library, and FileToWrite for the target path within the AV folder. An optional “c” flag simplifies copying the DLL to the specified location remotely.
The binary file comes with a PowerShell script, Run_Check.ps1, which automates the scanning of executable files in C:\Windows and recording those that are whitelisted for further exploitation.
See also: Defendnot tool disables Microsoft Defender

Users can customize the scenario for their environment, making it suitable for red team simulations or defensive assessments.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
