HomeSecurityWindows Defender: 12-year-old bug gives hackers administrator privileges

Windows Defender: 12-year-old bug gives hackers administrator privileges

Microsoft has fixed a privilege escalation vulnerability Defender Antivirus in Microsoft (formerly Windows Defender ) that could allow attackers to gain administrator privileges on vulnerable Windows computers .

Windows Defender
Windows Defender: 12-year-old bug gives hackers administrator privileges

According to Microsoft, Microsoft Defender Antivirus is the default antivirus program on more than 1 billion systems Windows 10.

The vulnerability, named CVE-2021-24092, affects older versions of Defender (from 2009 onwards) and client and server releases, starting with Windows 7 and later.

Attackers with basic user can exploit the vulnerability locally, in attacks that do not require user interaction.

Additionally, the vulnerability has been found to affect other Microsoft security products, including Microsoft Endpoint Protection, Microsoft System Center Endpoint Protection, Microsoft Security Essentials, and others.

SentinelOne researchers discovered and reported the vulnerability in November 2020. Microsoft released a patch on Tuesday , along with the February 2021 Patch Tuesday .

Windows Defender: 12-year-old bug gives hackers administrator privileges
Windows Defender: 12-year-old bug gives hackers administrator privileges

The vulnerability has existed for twelve years

The vulnerability was discovered in the BTR.sys driver, also known as the Boot Time Removal Tool.

According to SentinelOne, the vulnerability had not been discovered for twelve years. This is likely due to the way this particular mechanism is triggered.

We assume that this vulnerability remained undiscovered until now because the driver is usually not present on the hard drive. Apparently it was installed and activated when needed (with a random name) and then removed.“.

Windows systems should be updated to protect against this vulnerability.

Microsoft Defender
Windows Defender: 12-year-old bug gives hackers administrator privileges

Of course, even though the vulnerability appears to have not been exploited, criminals will likely figure out how to exploit it on vulnerable systems,” SentinelOne concluded.

Additionally, since the vulnerability exists in all versions of Windows Defender since 2009, many users may not be able to apply the patch , leaving their systems exposed to future attacks.“.

Source: Bleeping Computer

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS