Skip to main content

Windows Defender CFA Bypassed

A new Windows Defender security feature included in the Windows 10 Fall Creators Update, intended to provide additional protection against ransomware, appears to have been bypassed.
Report a cyber attack: call 0300 303 5222 or email [email protected]

This content has been archived

This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk

Summary

A new Windows Defender security feature included in the Windows 10 Fall Creators Update, intended to provide additional protection against ransomware, appears to have been bypassed.

Affected platforms

The following platforms are known to be affected:

Threat details

Controlled Folder Access (CFA) allows users to protect directories from modification by any application not on an allow list, with programmes manually added to this list. However, Windows allow lists all Office applications by default, meaning any malware that uses Office documents as a delivery vector is able to avoid CFA.


Remediation steps

Type Step

Microsoft have indicated that CFA is intended to be part of a layered security approach and should not be treated as a one-stop tool for preventing ransomware infection.

Additionally, users should:

  • ensure antivirus software and other security products are fully updated.
  • only open email attachments and other media from trusted sources.

Last edited: 23 June 2020 9:29 pm