Microsoft is moving antivirus programs from running at kernel level
#1
Exclamation 
Quote:Antivirus software will soon be moved out of the kernel mode in Windows. This change is part of Microsoft's Windows Resiliency Initiative (WRI).

Last year, millions of Windows PCs crashed with a blue screen due to a faulty update for Crowdstrike. In the aftermath of the incident, Microsoft held a security summit with the intention to prevent such issues in the future. Several security vendors, including Bitdefender, CrowdStrike, ESET, SentinelOne, Trellix, Trend Micro, and WithSecure, joined the Microsoft Virus Initiative (MVI) 3.0 program to collaborate with Microsoft and improve the security and reliability of Windows.

Microsoft says that it will release a private preview of the Windows endpoint security platform to its MVI partners. The changes will require antivirus software, and endpoint detection and response (EDR) apps, to run in user mode like most apps do. Microsoft highlights that running apps with administrator permissions opens the door to malware, which could infect a user's computer, and wreak havoc on critical system resources, causing disruptions, data loss, etc. This was what had caused the Crowdstrike BSODs last year.

Security vendors will be able to test their software, and request changes if required, to ensure that their antivirus products run fine in user mode. The Verge quotes David Weston, vice president of enterprise and OS security at Microsoft, who said that "We’re not here to tell them how the API should work, we’re here to listen and provide the security and reliability".

Continue Reading...
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
Android Security Bulletin—March 2026
Android Security B...harlan4096 — 11:13
Qualcomm unveils Wi-Fi 8 chip designed t...
Qualcomm has commi...harlan4096 — 11:10
Adobe Acrobat Reader DC 2025.001.21265
Adobe Acrobat Read...harlan4096 — 11:07
uBOLite 2026.301.2014 (already released ...
uBOLite 2026.301.2...harlan4096 — 11:06
NVIDIA GeForce Game Ready 595.71 driver
Highlights  Gam...harlan4096 — 11:05

[-]
Birthdays
Today's Birthdays
No birthdays today.
Upcoming Birthdays
avatar (44)gapedDow
avatar (38)snorydar
avatar (43)Hectorvot
avatar (51)knowhanPluts
avatar (39)Williamengiz
avatar (46)qaqapeti
avatar (44)battsourIonix
avatar (43)CedricSek
avatar (39)chasRex
avatar (43)slavrProck
avatar (45)Tyesharaike
avatar (49)TomeRerla
avatar (45)walllMIZ
avatar (41)oconyho
avatar (33)uteluxix
avatar (47)piafcflene
avatar (39)Matthewkah
avatar (51)tersfargum
avatar (50)alfreExept
avatar (38)Charlesfibre
avatar (42)napasvem
avatar (44)diploJeoca
avatar (38)francisnj3
avatar (43)artmaGoork
avatar (45)tukraNax
avatar (41)RichardCisee
avatar (40)ebenofit
avatar (38)ykazawu
avatar (41)ARYsahulatbazar

[-]
Online Staff
harlan4096's profile harlan4096
Administrator

>