Further Flaws Found in Microsofts Malware Protection Engine
This content has been archived
This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk
Summary
Affected platforms
The following platforms are known to be affected:
Threat details
The vulnerability itself is a type of memory corruption specific to the heap area of memory. It is located within the apicall function within MsMpEng that lies in the same un-sandboxed emulator as the previous vulnerability discussed in CC-1397. The emulator is used to execute untrusted files as part of the protection system and runs with full SYSTEM level privileges.
As with the last vulnerability, Google's Project Zero team privately disclosed the vulnerability to Microsoft who in turn silently pushed patches to all affected products.
Remediation steps
Last edited: 17 February 2020 11:31 am