Microsoft has added a new ransomware firewall called Controlled Folder Access, which can prevent unknown programs from modifying critical system files. At DerbyCon security conference , a security researcher demonstrated how it's possible to bypass this new security system using DLL injections.

Controlled Folder Access is a new feature that protects folders on our computer, as well as the files contained in those folders. When applied to a folder, the files and subfolders contained within it can be edited only by applications that the user marks as safe (whitelist), or by programs that Microsoft deems safe.
Knowing that explorer.exe is on Microsoft's whitelist, security researcher Soya Aoyamafound a way to inject malicious DLLs into the explorer.exe process. Since Microsoft has whitelisted the program, when the DLL is executed through it, it can make changes to files and folders that are protected by Controlled Folder Access.
Unfortunately, so far this particular vulnerability is still active and anyone can exploit it. Also, when malicious code is executed in this way, Windows Defender does not recognize it, just as well-known antivirus programs with malware protection do not recognize it, such as Avast, ESET, Malware Bytes and McAfee.
Aoyama, before publicly showing the way this Controlled Folder Access breach is possible, had already informed Microsoft of his finding, although the company did not consider it a vulnerability that needed to be fixed, nor did it deem that the researcher who discovered it should be rewarded.
