Cybercriminals can exploit a vulnerability affecting Microsoft Defender antivirus in Windows. The vulnerability allows malicious users to learn locations that are excluded from antivirus scanning, and install malware there.

According to some users, this issue has been around for at least eight years and affects Windows 10 21H1 and Windows 10 21H2.
See also: Ransomware gang that affected over 50 companies arrested
Lax permissions
Microsoft Defender allows users to add locations (local or network) on their systems that are excluded from malware scans. People often choose to exclude certain items from scanning to avoid affecting the functionality of legitimate applications, as antivirus can sometimes misidentify them as malware.
This means that some applications are not scanned and therefore have no protection. If a malicious user learns which of these unprotected applications are, they can infect them with malware.
Security researchers have discovered that the list of sites excluded from Microsoft Defender scanning is not protected and can be accessed by any local user.
Regardless of their permissions, local users can query the registry and learn the paths that Microsoft Defender is not allowed to scan.
See also: Apple: Fixes DoorLock bug that disables iPhones and iPads

Antonio Cocomazzi, a threat researcher at SentinelOne, says there is no protection for this information.
Another security expert, Nathan McNulty, confirmed that the issue exists in Windows 10 versions 21H1 and 21H2, but stressed that it does not affect Windows 11.
A threat actor needs local access to learn which locations are exempt from Microsoft Defender scanning. However, that doesn’t mean there’s no risk. Many attackers are already on compromised corporate networks and are looking for a way to move through them as quietly as possible.
See also: Man jailed for spying on teenagers and stealing photos
Knowing the Microsoft Defender exclusion list, a threat actor that has already compromised a Windows machine can store and execute malware without fear of being detected by the antivirus.
This Microsoft Defender weakness has been pointed out in the past by Paul Bolton:

Since Microsoft has not yet addressed the issue, network administrators should be very careful and ensure that Microsoft Defender exceptions are configured correctly.
Source: Bleeping Computer
