Critical Windows Defender security flaw left PCs vulnerable

Microsoft has issued a patch for a remote code execution vulnerability in the Microsoft Malware Protection Engine.
Remote execution in the program which was not designed for remote excution? It probably was...

All version of Windows affected. You should never run programs with LocalSystem authority. Even if it is antivirus for scanning...Scanning?...hehe.
 
I was reading through the attack and the documentation this morning. This was an INSANE hole to have in security. It wouldn't have mattered how good your IIS setup was, you were vulnerable anyway, and there was no way to detect the intrusion on your network, and no way to log it.

This, plus a virtual machine escape, would have been nightmarish to deal with.
 
Top
Sign up to the MyBroadband newsletter
X