HomeSecurityWindows Defender: Microsoft's Antivirus Security Insufficient

Windows Defender: Microsoft's Antivirus Security Insufficient

Despite Microsoft's recent efforts to address vulnerabilities that could expose Windows users to risk, it seems that the company's developers still have a lot of work to do, as Windows Defender is still vulnerable to hacking attacks.

Windows

Recent Windows Defender security updates released by Microsoft have proven to be insufficient, as the antivirus is still vulnerable to a number of remote code execution vulnerabilities.

Security researcher James Lee has revealed that Windows Defender 's Microsoft Malware Protection Engine (MsMpEng) is vulnerable to remote code execution due to inadequate sandboxing , a problem that other security experts have also pointed out in recent months. 

Sandboxing is the process of running software or a file on an isolated system and observing the results. If it is "clean", then it is allowed to run on production systems.

The lack of adequate sandboxing was also highlighted by Google researcher Tavis Ormandy and Project Zero security analyst Mateusz Jurczyk, through the identification of critical security vulnerabilities.

Tavis Ormandy, who has occasionally revealed significant bugs in Microsoft software, had identified some critical vulnerabilities in Windows Defender, which he reported to the company for their repair.

Following the release of corresponding patches for all of the aforementioned vulnerabilities, Ormandy revealed in a new tweet on June 7 that Windows Defender is affected by “more critical remote mpengine vulnerabilities,” explaining that the antivirus engine should be “sandboxed.

The same problem is highlighted in today's report by researcher James Lee, who discovered two more remote code execution vulnerabilities that allow compromised systems to be compromised, despite the latest patches released by Microsoft.

It appears that the new security vulnerabilities are unrelated to those reported by Ormandy earlier this month.

Microsoft has yet to make any official statement regarding the new Windows Defender vulnerabilities reported, the disclosure of which comes just days after the established Patch Tuesday, where the company typically addresses security vulnerabilities in its software.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS