EDR-Freeze tool suspends security software using Windows WER
Summary
Hide β²
Show βΌ
A new proof-of-concept tool called EDR-Freeze exploits Windows Error Reporting (WER) to suspend security software, including EDR and antivirus tools. The technique, discovered by researcher Zero Salarium, operates from user mode without requiring a vulnerable driver. It leverages legitimate Windows components to indefinitely suspend security processes. The method involves using the WerFaultSecure component and the MiniDumpWriteDump API to suspend all threads in the target process, effectively putting security software into a dormant state. This approach is stealthier and more efficient than traditional BYOVD attacks, which rely on exploiting vulnerable kernel drivers. The tool has been successfully tested on Windows 11 24H2, demonstrating its potential impact on modern systems.
Timeline
-
22.09.2025 20:07 π° 1 articles Β· β± 13h ago
EDR-Freeze tool suspends security software using Windows WER
A new proof-of-concept tool called EDR-Freeze has been developed to suspend security software, including EDR and antivirus tools, by exploiting Windows Error Reporting (WER). The technique, discovered by researcher Zero Salarium, operates from user mode without requiring a vulnerable driver. It leverages the WerFaultSecure component and MiniDumpWriteDump API to suspend all threads in the target process, effectively putting security software into a dormant state. The tool has been successfully tested on Windows 11 24H2, demonstrating its potential impact on modern systems. Defending against this method involves monitoring WER for suspicious process identifiers and potentially hardening Windows components against abuse.
Show sources
- New EDR-Freeze tool uses Windows WER to suspend security software β www.bleepingcomputer.com β 22.09.2025 20:07
Information Snippets
-
EDR-Freeze operates from user mode, eliminating the need for a vulnerable driver.
First reported: 22.09.2025 20:07π° 1 source, 1 articleShow sources
- New EDR-Freeze tool uses Windows WER to suspend security software β www.bleepingcomputer.com β 22.09.2025 20:07
-
The technique leverages the WerFaultSecure component and MiniDumpWriteDump API to suspend security processes.
First reported: 22.09.2025 20:07π° 1 source, 1 articleShow sources
- New EDR-Freeze tool uses Windows WER to suspend security software β www.bleepingcomputer.com β 22.09.2025 20:07
-
The method involves a race condition attack that suspends the target process indefinitely.
First reported: 22.09.2025 20:07π° 1 source, 1 articleShow sources
- New EDR-Freeze tool uses Windows WER to suspend security software β www.bleepingcomputer.com β 22.09.2025 20:07
-
EDR-Freeze has been tested successfully on Windows 11 24H2.
First reported: 22.09.2025 20:07π° 1 source, 1 articleShow sources
- New EDR-Freeze tool uses Windows WER to suspend security software β www.bleepingcomputer.com β 22.09.2025 20:07
-
The tool was developed by security researcher Zero Salarium.
First reported: 22.09.2025 20:07π° 1 source, 1 articleShow sources
- New EDR-Freeze tool uses Windows WER to suspend security software β www.bleepingcomputer.com β 22.09.2025 20:07
-
Defending against EDR-Freeze involves monitoring WER for suspicious process identifiers.
First reported: 22.09.2025 20:07π° 1 source, 1 articleShow sources
- New EDR-Freeze tool uses Windows WER to suspend security software β www.bleepingcomputer.com β 22.09.2025 20:07