Windows Defender CFA Bypassed
A new Windows Defender security feature included in the Windows 10 Fall Creators Update, intended to provide additional protection against ransomware, appears to have been bypassed.
This content has been archived
This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk
Summary
A new Windows Defender security feature included in the Windows 10 Fall Creators Update, intended to provide additional protection against ransomware, appears to have been bypassed.
Affected platforms
The following platforms are known to be affected:
Threat details
Controlled Folder Access (CFA) allows users to protect directories from modification by any application not on an allow list, with programmes manually added to this list. However, Windows allow lists all Office applications by default, meaning any malware that uses Office documents as a delivery vector is able to avoid CFA.
Remediation steps
Last edited: 23 June 2020 9:29 pm