Bug In Microsoft Defender Now Allow Malware Downloads

23 112
Avatar for Secure
Written by
4 years ago

A security researcher has found a bug in anti-malware  Microsoft Defender software that potentially allows downloading malicious code or spyware. The issue has been identified after a recent product feature update.



In particular, MpCmdRun.exe receives an update from the Microsoft Malware Security Command Line tool, which now allows users to download files from a remote location.


Although the feature itself isn't malicious, the attacker could manipulate this feature to loading malicious programs onto a target computer.
It is a serious problem theoretically because everyone has the potential to transfer malicious files to the target computer using the protection tool itself.

Although it is a LOLBin (living off the country) it is very difficult to use, because Windows Defender will search each file until it is downloaded. If any malicious file is found, it will then automatically block it.

Hey, check out this Free Online Image Hosting service and sharing Platform.

which have Great features that Allow you to host any image format from JPG, PNG, BMP, WEBP AND GIF

plus allow SEO ranking on images (edit the title) and customised whether to set your image private or not? gives you total control of your privacy

https://free-tool.online/ very soon advance photo editor will be added to its feature

38
$ 0.00
Sponsors of Secure
empty
empty
empty
Avatar for Secure
Written by
4 years ago

Comments

valuable informatio... Thanks support me please

$ 0.00
4 years ago

You are welcome

$ 0.00
4 years ago

It is very difficult to use

$ 0.00
4 years ago

No @adnanadi it not very difficult to use That why security researchers argue why it necessary for Microsoft to patch this before it gets out of hand

$ 0.00
4 years ago

This info is very nice and helpful plz support me and subscribe my account & also give some like & comments

$ 0.00
4 years ago

Plz subscribe me ❤️ nice

$ 0.00
4 years ago

Well am absolutely sure these softwares such as Window defender are made to accept malwares on purpose at some point. Just like how softwares like Adobe Photoshop are made both original type and malware type just to protect it from being taken without payment and approval first.

$ 0.00
4 years ago

No stella Adobe came out when accused of such thing and state that they didn't create two version but only one but in this case Microsoft Defender is a whole lot different from Adobe this time Microsoft them self implanted this Microsoft Malware Security Command Line and the purpose was to scan and detect any malicious software and block it before it harm the pc but it turn out to be the other way round

$ 0.00
4 years ago

Well am pretty sure these malware creators are smart too. I hope Microsoft will be able to handle this issue before it gets out of hand.

$ 0.00
4 years ago

Yeah 😄

$ 0.00
4 years ago

I don't know but this is funny as hell. Using the Windows Defender to download malicious software...

$ 0.00
4 years ago

Good. This hoodis a head.

$ 0.00
4 years ago

Good. This hoodis a head.

$ 0.00
4 years ago

This is not good news at all. I hope they release an update or fix for it soon before those with malicious intent begin to exploit the vulnerability. Has there been any official statement from Microsoft on the issue?

$ 0.00
User's avatar M3i
4 years ago

In a statement to Forbes, a Microsoft spokesperson confirmed yes that an update will be released soon and Despite these reports, Microsoft Defender antivirus and Microsoft Defender ATP will still protect customers from malware. These programs detect malicious files downloaded to the system through the antivirus file download feature.

$ 0.00
4 years ago

Thank you for your prompt response. It's highly appreciated.

$ 0.00
User's avatar M3i
4 years ago

you are welcome

$ 0.00
4 years ago

Great article

$ 0.00
4 years ago