HomeUpdatesMicrosoft: Fixes a bug in Defender that allows malware scans to be bypassed

Microsoft: Fixes Defender bug that allowed malware scans to be bypassed

Microsoft recently fixed a bug in Microsoft Defender Antivirus that allowed malicious users to plant and execute malicious payloads without Defender's malware detection engine being triggered. In short, the bug prevented malware detection.

This bug affected the latest versions of Windows 10 and attackers could have been using it since at least 2014.

See also: Microsoft Defender Preview is available for Windows and Android

Microsoft Defender malware

As we mentioned earlier, Microsoft Defender allows users to add locations (local or network) on their systems that are excluded from malware scans. Users typically choose to exclude certain items from scanning to avoid affecting the functionality of legitimate applications, as sometimes the antivirus can incorrectly detect them as malware.

This means that some apps are not scanned and therefore have no protection. If a malicious user learns which apps are not protected, they can infect them with malware without being detected by Microsoft Defender.

Security researchers have discovered that the list of sites excluded from Microsoft Defender scanning is not protected and can be accessed by any local user.

Exploitation of the bug was possible because the Registry key was accessible by the 'Everyone' group, as shown in the image below.

Microsoft: Fixes Defender bug that allowed malware scans to be bypassed

Regardless of their permissions, local users could query the registry and learn the paths that Microsoft Defender was not allowed to scan.

See also: Microsoft: How does it plan to limit malware distribution through Office documents?

Once attackers could learn which assets were unprotected, they could also deliver and execute malware from a blocked folder on a compromised Windows system, without having to fear that the malicious payload would be detected and neutralized by Microsoft Defender.

According to BleepingComputer, someone could exploit this vulnerability to execute a ransomware sample and encrypt a Windows system without any warnings or signs of detection from Microsoft Defender.

error

Microsoft addresses security issue

According to Dutch security expert SecGuru_OTX, Microsoft has now fixed the vulnerability via an update.

SentinelOne threat researcher Antonio Cocomazzi confirmed that the flaw can no longer be exploited on Windows 10 20H2 systems after installing the February 2022 Patch Tuesday.

Learn more: Patch Tuesday February 2022: Microsoft fixes 48 vulnerabilities

Some users are seeing the new permissions change after installing the February 2022 Patch Tuesday Windows cumulative updates.

On the other hand, Will Dormann, a vulnerability analyst for CERT/CC, noted that he received the permission change without installing any updates, suggesting that the change could be added by both Windows updates and Microsoft Defender security intelligence updates.

As BleepingComputer was also able to confirm, the Windows Advanced Security Settings permissions for Defender exceptions have indeed been updated, with the 'Everyone' group removed from the Registry key's permissions.

On Windows 10 systems, where this change has already been rolled out, users must now have administrator privileges to be able to access the list of applications excluded from Microsoft Defender scanning.

Source: Bleeping Computer

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS