Microsoft Fixes Critical Windows 10 Security Flaw Affecting Windows Defender

Advertisement
By Jagmeet Singh | Updated: 4 April 2018 18:25 IST
Highlights
  • Microsoft has rolled out security updates
  • The updates patches critical remote execution vulnerability
  • It majorly affects Windows Defender on Windows and Windows Server

Microsoft has rolled out a bunch of security updates to patch a critical remote execution vulnerability that majorly affects Windows Defender on Windows and Windows Server platforms. The issue, listed as CVE2018-0986, exists within Microsoft Malware Protection Engine also impacts Microsoft Security Essentials, Microsoft Forefront EndPoint Protection 2010, Microsoft Exchange Server 2013 and 2016, and Windows Intune Endpoint Protection. Enterprise administrators and end users will not be required to install updates manually as there are built-in tools to automatically deploy the updates within 48 hours of their release.

The new updates aren't a part of Microsoft's monthly security update phase. However, it tightens security across various Windows platforms, including Windows 10 and Windows Server 2012. "An attacker who successfully exploited this vulnerability could execute arbitrary code in the security context of the LocalSystem account and take control of the system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights," the company wrote while describing the vulnerability on its Security TechCenter.

Microsoft points out that there are "many ways" that a specially crafted file can be placed by the attacker. Moreover, it could be delivered via a website, email, or an instant messenger message or even through a site that accepts or host user-provided content.

Advertisement

"If real-time scanning is not enabled, the attacker would need to wait until a scheduled scan occurs in order for the vulnerability to be exploited. All systems running an affected version of antimalware software are primarily at risk," Microsoft notes.

Advertisement

The security updates essentially correct the manner in which the Microsoft Malware Protection Engine scans specially crafted files. Further, the vulnerable Microsoft Malware Protection Engine version 1.1.14600.4 has been updated to version 1.1.14700.5.

 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Advertisement

Related Stories

Popular Mobile Brands
  1. Nothing Announces Offers on Phones, Wearables During Flipkart Sale
  2. Vivo Y31 Series With 6,500mAh Battery Launched in India: See Price
  3. Samsung Begins Rolling Out One UI 8 Update to the Galaxy S25 Series
  4. [Exclusive] Noise to Launch Flagship Master Series Over-Ear Headphones Soon
  5. Flipkart Big Billion Days Sale: Discounts on Motorola Phones Announced
  6. Samsung Galaxy S25 FE With 50-Megapixel Camera Launched in India: See Price
  7. Samsung Galaxy S26 Ultra, Galaxy S26 Pro Charging Speed Leaked
  8. iOS 26 Update Brings These New Features to AirPods Pro 3, Pro 2, AirPods 4
  9. Samsung Galaxy S26 Series May Launch With This In-House Exynos Chip
  10. iOS 26 Released Alongside iPadOS 26, macOS Tahoe: Here's How to Download It
  1. Samsung Galaxy S26 Ultra, Galaxy S26 Pro Charging Speed Listed on Certification Website
  2. Apple's AirPods Pro 3, Pro 2, and AirPods 4 Get Firmware Update With New iOS 26 Features
  3. Samsung Galaxy S26 Series to Launch With In-House 2nm Exynos 2600 Chipset: Report
  4. Meta Ray-Ban Display With Heads-Up Display and sEMG Wristband Leaked Ahead of Meta Connect 2025
  5. The Witcher Season 4 Release Date Revealed: Know When and Where to Watch It Online
  6. iOS 26 Update Released Alongside iPadOS 26 and macOS Tahoe: Check Eligible Models, How to Download
  7. Scientists Propose Space Missions to Chase Down Interstellar Comets
  8. Iceland Plume Discovery Reveals Ancient Volcanic Funnels Across North Atlantic
  9. Huawei Watch Ultimate 2 Design Renders Leaked, Could Launch Soon
  10. Marvel's Wolverine Will Reportedly Launch in 2026; Insomniac's Venom Game in 'Active Development'
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.