What is WinRing0 and why does Windows Defender block it?

  • WinRing0 is a driver that allows low-level hardware access in Windows.
  • Microsoft Defender identifies it as a threat due to past vulnerabilities.
  • Numerous monitoring and control apps depend on this driver.
  • The debate between functionality, security, and certification costs continues.

WinRing0

In recent weeks, thousands of Windows users have encountered an unexpected situation: tools they've long used to control fans, monitor temperatures, or customize their computers' RGB lighting have suddenly stopped working. The culprit appears to be an old acquaintance: WinRing0 , a low-level operating system access driver that, following a Microsoft Defender update , has begun to be identified as a security threat.

But what exactly is WinRing0 , and why has it raised so many alarms? Is it really a virus or a false positive? To understand this, we need to delve into how many of the utilities we use daily to manage PC hardware work. This article will explain in detail what's behind the WinRing0 blocking and what solutions are being considered in the industry.

What is WinRing0 and what is it used for?

WinRing0 is an open-source driver that allows programs to access system hardware directly, bypassing the operating system's abstraction layers. This makes it especially useful for applications that require accurate, real-time information about the hardware's status , such as temperature monitors, fan controllers, or benchmarking tools.

Popular programs like Fan Control, Open Hardware Monitor, HWiNFO, CapFrameX, and SignalRGB have used WinRing0 in their monitoring functions or advanced settings such as fan speed and RGB effects. This driver acts as an intermediary between the software and the hardware, and its main advantage is that it can directly access the system's memory registers and segments.

The reason so many applications use it is simple: there are very few free, widely compatible, and relatively secure options that allow this type of access in Windows. And until recently, WinRing0 perfectly fulfilled this function without causing problems. Until now.

WinRing0 drivers identified as a threat

Why Windows Defender now flags it as a threat

Everything exploded in mid-March 2025, when Windows Defender began classifying WinRing0 as a "hacktool" or malware . Microsoft's security tool started automatically blocking it, causing any application that used it to stop working correctly. This caused chaos among users, who overnight lost basic functions of their favorite system control applications.

Immediately, the fans began spinning uncontrollably at full speed, the RGB lighting became erratic, and programs wouldn't even launch . The tech community mobilized to understand what was happening, and they soon discovered that the root cause was that WinRing0, or rather its problematic history, had once again put it in Microsoft's crosshairs.

The key reason lies in a vulnerability registered under the code CVE-2020-14979 , discovered in 2020. This vulnerability allowed processes without administrator privileges to read and write to arbitrary memory locations. In practice, this could be exploited to escalate privileges and control the compromised system. Although it is an older version, Microsoft has decided to be stricter and consider any version without a recent digital signature as dangerous , even if the vulnerability is no longer active.

False positive or real threat?

The controversy is brewing. Many developers and security experts believe the driver itself poses no danger when used with trusted software. In fact, Remi Mercier, developer of Fan Control, asserts that most of the affected tools are legitimate and that this is a widespread false positive.

However, others point out that, while the driver isn't malware by default, it does open the door to potential attacks if someone manipulates or uses it maliciously. Its ability to grant unrestricted access to the Windows kernel makes it an attractive target for cybercriminals.

Microsoft, for its part, has stated that it will maintain its policy of blocking unsigned drivers and is reviewing its detection algorithms to avoid false positives. Meanwhile, users must choose between discontinuing the use of these tools or manually adding exceptions in Windows Defender , something not everyone recommends due to the security implications.

winring0

Which programs and users have been affected?

The list of affected software is extensive. Any application that depends on WinRing0 has been compromised to some degree . Here are some of the most important ones:

  • Fan control
  • CapFrameX
  • OpenRGB
  • HWiNFO
  • Libre Hardware Monitor
  • Razer Synapse
  • SteelSeries Engine
  • MSI Afterburner
  • ZenTimings

Reported problems range from general instability to uncontrolled fans , loss of access to sensors, and runtime errors. Some users have managed to resolve the issue by adding exceptions in their antivirus software, but many consider this dangerous, especially if they don't know how to identify safe driver versions.

Alternatives to WinRing0 and the digital signature problem

Faced with this crisis, some developers are removing WinRing0 from their tools , replacing it with alternative drivers . The problem is that Microsoft now requires any kernel access driver to be digitally signed, and to obtain this, the developer must be a registered company and pay significant fees. Open-source or individual projects, unless they have external funding or support, can hardly meet this requirement.

This is where iBuyPower , the popular gaming PC brand, comes in , announcing its intention to sponsor a modern, signed version of WinRing0 so that all developers can use it without being blocked by Windows Defender.

winring0

What about long-term security?

Even if a signed and secure version of WinRing0 can be reinstated, the core of the debate remains security . These types of drivers allow deep access to the system, and even if they are signed, if an attacker manages to forge that signature, they could exploit the same entry point.

Therefore, some experts propose that the only stable solution is for Microsoft to offer an official driver, audited and maintained by them , that allows access to the hardware under certain controlled conditions. This would eliminate the need to use third-party drivers that are prone to maintenance errors or misuse.

What began as a false positive has uncovered a vulnerability known for years and has forced the industry to seek alternative solutions that don't rely on high-risk drivers. While a temporary solution might come from iBuyPower, the current trend is to move away from WinRing0 and toward new, more secure and regulated hardware access standards.

And when it comes to the system kernel, even a small vulnerability can have a global effect.


Add as preferred source in Google