ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

Microsoft Issues Patches for Defender Zero

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2021-1647
Remote Code Execution Vulnerability in Microsoft Defender Antimalware Engine

CVE-2021-1647 is a remote code execution flaw in Microsoft Defender's antimalware engine, categorized by CISA as a heap-based buffer overflow (CWE-122) arising from improper validation of crafted input values (CWE-1285). It is triggered when the Defender engine processes maliciously crafted content, for example a crafted file delivered via email or the web that Defender scans, causing the overflow during processing. Successful exploitation lets an attacker run arbitrary code on the target machine in the context of the Defender process, potentially leading to full system compromise. Any system running the affected Defender engine is exposed, including Windows 10 and Windows Server deployments where Defender is the default or widely deployed antivirus; the source data provides no fixed version numbers, only the vendor-issued update. The flaw is listed in CISA's Known Exploited Vulnerabilities catalog as of 2021-11-03, indicating exploitation has been observed in the wild, though no public PoC is known and ransomware use is listed as unknown.

Do: Apply Microsoft's Defender antimalware engine/platform updates per vendor instructions and ensure Defender security intelligence and platform updates are enabled everywhere, including infrequently updated servers and endpoints. After updating, verify the Defender engine version on high-value hosts is current, prioritizing systems listed in CISA KEV remediation requirements.

7.839% KEV
  • Microsoft Defender (antimalware engine, e.g., Microsoft Defender Antivirus / Microsoft Defender for Endpoint) Versions running the Defender antimalware engine prior to Microsoft's security update for CVE-2021-1647; exact affected and fixed version ranges are not specifi
mass≈1 billion+ Windows devices (Defender is the built-in AV on Windows 10 and ships broadly on Windows Server)
CVE-2021-1674
+1 in the same advisory: …1648
Windows Remote Desktop Protocol Core Security Feature Bypass Vulnerability

Windows Remote Desktop Protocol Core Security Feature Bypass Vulnerability

NVD description · AI analysis pending
8.8
group max
3%
  • microsoft windows 10
  • microsoft windows 7
  • microsoft windows 8.1
  • +1 more
CVE-2021-1705
Microsoft Edge (HTML-based) Memory Corruption Vulnerability

Microsoft Edge (HTML-based) Memory Corruption Vulnerability

NVD description · AI analysis pending
4.22%
  • microsoft edge
Full article478 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananJan 13, 2021

For the first patch Tuesday of 2021, Microsoft released security updates addressing a total of 83 flaws spanning as many as 11 products and services, including an actively exploited zero-day vulnerability.

The latest security patches cover Microsoft Windows, Edge browser, ChakraCore, Office and Microsoft Office Services, and Web Apps, Visual Studio, Microsoft Malware Protection Engine, .NET Core, ASP .NET, and Azure. Of these 83 bugs, 10 are listed as Critical, and 73 are listed as Important in severity.

The most severe of the issues is a remote code execution (RCE) flaw in Microsoft Defender (CVE-2021-1647) that could allow attackers to infect targeted systems with arbitrary code.

Microsoft Malware Protection Engine (mpengine.dll) provides the scanning, detection, and cleaning capabilities for Microsoft Defender antivirus and antispyware software. The last version of the software affected by the flaw is 1.1.17600.5, before it was addressed in version 1.1.17700.4.

The bug is also known to have been actively exploited in the wild, although details are scarce on how widespread the attacks are or how this is being exploited. It's also a zero-click flaw in that the vulnerable system can be exploited without any interaction from the user.

Microsoft said that despite active exploitation, the technique is not functional in all situations and that the exploit is still considered to be at a proof-of-concept level, with substantial modifications required for it to work effectively.

What's more, the flaw may already be resolved as part of automatic updates to the Malware Protection Engine — which it typically releases once a month or as when required to safeguard against newly discovered threats — unless the systems are not connected to the Internet.

"For organizations that are configured for automatic updating, no actions should be required, but one of the first actions a threat actor or malware will try to attempt is to disrupt threat protection on a system so definition and engine updates are blocked," said Chris Goettl, senior director of product management and security at Ivanti.

Tuesday's patch also rectifies a privilege escalation flaw (CVE-2021-1648) introduced by a previous patch in the GDI Print / Print Spooler API ("splwow64.exe") that was disclosed by Google Project Zero last month after Microsoft failed to rectify it within 90 days of responsible disclosure on September 24.

Other vulnerabilities fixed by Microsoft include a memory corruption flaws in Microsoft Edge browser (CVE-2021-1705), a Windows Remote Desktop Protocol Core Security feature bypass flaw (CVE-2021-1674, CVSS score 8.8), and five critical RCE flaws in Remote Procedure Call Runtime.

To install the latest security updates, Windows users can head to Start > Settings > Update & Security > Windows Update, or by selecting Check for Windows updates.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2021/01/microsoft-issues-patches-for-defender.html