Google security engineer Tavis Ormandy has discovered yet another vulnerability in Windows Defender, and once again Microsoft has moved very quickly to provide a solution.

Ormandy, who is a member of Google's Project Zero security program, discovered the vulnerability on June 9 and reported it to Microsoft privately to give the software giant a chance to release a patch. According to Project Zero's policy, vulnerabilities are disclosed 90 days after the vendor is notified if a patch hasn't been released in the meantime.
However, Microsoft released a patch for this Windows Defender, so Ormandy published details on Friday, showing once again that without sandboxing, the antivirus engine is prone to similar security issues.
For most tech-savvy users, Ormandy explains that the bug affects the x86 emulator built for Windows Defender, which Microsoft has left in the dark.
Microsoft has already released an updated code version for this vulnerability and, to stay safe, Windows Defender must update the malware protection engine to version 1.1.13903.0. To determine the version running on your system, open the Settings app in Windows 10, go to the Update & Security > Windows Defender section and check the engine version on the right side of the screen.
Windows 10 systems that have been configured to receive automatic updates have already been updated and are protected from this vulnerability.
As for Microsoft, it appears that the software giant indeed responds quickly to these security warnings, although it remains astonishing to see the company prefer to patch the vulnerability rather than break the protective box from the virus to prevent such flaws.
