Skip to main content

Further Flaws Found in Microsofts Malware Protection Engine

Another critical vulnerability has been identified in Microsoft's Malware Protection Engine, a key component within Windows Defender and other Microsoft anti-malware products that could result in vulnerable user becoming compromised through simply visiting a webpage or receiving a crafted email.
Report a cyber attack: call 0300 303 5222 or email [email protected]

This content has been archived

This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk

Summary

Another critical vulnerability has been identified in Microsoft's Malware Protection Engine, a key component within Windows Defender and other Microsoft anti-malware products that could result in vulnerable user becoming compromised through simply visiting a webpage or receiving a crafted email.

Threat details

The vulnerability itself is a type of memory corruption specific to the heap area of memory. It is located within the apicall function within MsMpEng that lies in the same un-sandboxed emulator as the previous vulnerability discussed in CC-1397. The emulator is used to execute untrusted files as part of the protection system and runs with full SYSTEM level privileges.

As with the last vulnerability, Google's Project Zero team privately disclosed the vulnerability to Microsoft who in turn silently pushed patches to all affected products.


Remediation steps

Type Step
  • Check all affected products are configured correctly and receiving updates. Updates to the Microsoft Malware Protection Engine will automatically be installed along with the updated malware definitions for the affected products.
  • Administrators of enterprise antimalware deployments should ensure that their update management software is configured to automatically approve and distribute engine updates and new malware definitions. Enterprise administrators should also verify that the latest version of the Microsoft Malware Protection Engine and definition updates are being actively downloaded, approved and deployed in their environment.


 


Last edited: 17 February 2020 11:31 am