ZeroHour

CVE-2021-1647

KEVmass

Remote Code Execution Vulnerability in Microsoft Defender Antimalware Engine

CISA: Microsoft Defender Remote Code Execution Vulnerability

CVSS 3.1
7.8 high
EPSS
39%p99
Published
()
KEV added
AI analysis

CVE-2021-1647 is a remote code execution flaw in Microsoft Defender's antimalware engine, categorized by CISA as a heap-based buffer overflow (CWE-122) arising from improper validation of crafted input values (CWE-1285). It is triggered when the Defender engine processes maliciously crafted content, for example a crafted file delivered via email or the web that Defender scans, causing the overflow during processing. Successful exploitation lets an attacker run arbitrary code on the target machine in the context of the Defender process, potentially leading to full system compromise. Any system running the affected Defender engine is exposed, including Windows 10 and Windows Server deployments where Defender is the default or widely deployed antivirus; the source data provides no fixed version numbers, only the vendor-issued update. The flaw is listed in CISA's Known Exploited Vulnerabilities catalog as of 2021-11-03, indicating exploitation has been observed in the wild, though no public PoC is known and ransomware use is listed as unknown.

What to do: Apply Microsoft's Defender antimalware engine/platform updates per vendor instructions and ensure Defender security intelligence and platform updates are enabled everywhere, including infrequently updated servers and endpoints. After updating, verify the Defender engine version on high-value hosts is current, prioritizing systems listed in CISA KEV remediation requirements.

Affected
Microsoft Defender (antimalware engine, e.g., Microsoft Defender Antivirus / Microsoft Defender for Endpoint)Versions running the Defender antimalware engine prior to Microsoft's security update for CVE-2021-1647; exact affected and fixed version ranges are not specifi
Estimated exposure
mass≈1 billion+ Windows devices (Defender is the built-in AV on Windows 10 and ships broadly on Windows Server) — Microsoft Defender is the default antivirus on Windows 10 and is deployed on a large share of Windows Server hosts, and the Windows installed base is on the order of a billion devices, so any system running the unpatched engine is…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Microsoft Defender Remote Code Execution Vulnerability

CISA Known Exploited Vulnerability
Affected
Microsoft Defender
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
microsoft
Products
windows defender, security essentials, system center endpoint protection
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news