A recent update to Microsoft Defender for Windows 10may allow malware and other files to be downloaded to a Windows.

Legitimate files that can be misused for malicious purposes are known as live-off-the-land binaries, or LOLBINs.
In the recent update that Microsoft Defender received, the MpCmdRun.exe may allow malicious files to be downloaded from a remote location.
Following this twist, Microsoft Defender is yet another Windows program that a malicious actor can exploit to carry out attacks.
Microsoft Defender: can be used as LOLBIN
Security researcher Mohammad Askarwas the first to discover that the recent update to the Microsoft Defender command-line tool now includes a new feature in the DownloadFile command-line.
This feature allows a local user to use the Microsoft Antimalware Service Command Line Utility (MpCmdRun.exe) to download a file from a remote location by using the following command:
MpCmdRun.exe -DownloadFile -url [url] -path [path_to_save_file]
According to information published by BleepingComputer, this feature was added to Microsoft Defender in version 4.18.2007.9 or 4.18.2009.9.
As you can see below, the resources.exe file has downloaded a sample of the WastedLocker Ransomware that was used in a recent Garmin.

The good news is that Microsoft Defender is able to detect malicious files downloaded with MpCmdRun.exe, but it is unknown whether other AV software will allow this program to bypass their commands. With this discovery, program administrators and partners now have an additional Windows executable to monitor so that it is not used against them.
