Microsoft

Microsoft Defender vulnerability: A big gateway for hackers

There have been negative headlines about Microsoft Defender in recent months. A vulnerability has now been discovered that could make it easy for hackers to circumvent the security solution’s protective function. Microsoft has not yet responded to this. Microsoft Defender allows hackers to bypass malware detection through a design weakness – this basically makes Defender useless as a security solution. This is about the Microsoft Defender exclusion list.

This list allows users to choose whether there should be locations (local and network) that are excluded from the security scan. The problem: The list is insufficiently secured, it is even almost unprotected. That reports that Online magazine Bleeping Computer. This vulnerability in Microsoft Defender is not new and was made public by Paul Bolton around eight years ago. Threat actors can exploit this vulnerability in Microsoft Defender antivirus protection on Windows to learn places excluded from scanning and inject malware right there.

According to the information, the problem has existed for at least eight years and now also affects the current versions Windows 10 21H1 and Windows 10 21H2. However, Windows 11 is not affected.

problem in permissions

As with any antivirus solution, Microsoft Defender allows users to add locations (local or network) on their systems that should be excluded from malware scans. Typically, exceptions are set to prevent antivirus programs from interfering with the functionality of legitimate applications that are mistakenly identified as malware. – this happens more often, especially when there is a lot of network traffic.

Conversely, this also means that these reject lists are extremely attractive to attackers and therefore actually deserve the highest level of protection. Security researchers discovered that the list of locations excluded from Microsoft Defender scan is unprotected and accessible to any local user. Regardless of their permissions, local users can query the registry to learn the paths that Microsoft Defender doesn’t scan for malware or dangerous files. This puts a list of barn-door-like open gateways into the hands of potential attackers.

Another problem with this is that Microsoft Defender on a server has automatic exclusions that are activated when certain roles or features are installed. Since these are not custom locations, they are even easier for hackers to exploit. Although an attacker needs local access to get to the Microsoft Defender exclusion list, this is not a major obstacle. Many attackers are already on compromised corporate networks and are looking for a way to evolve as silently as possible. Microsoft has not yet recognized the problem as such and made a change – at least not for Windows 10.

Recent Posts

Austin Fence Installation Contracts: 12 Clauses Homeowners Should Check in 2026

A fence proposal becomes useful only when it explains what will be built, who owns…

6 hours ago

Mouse for MMO players: Razer’s new Naga V3 Pro is a button monster

Razer is launching a new MMO mouse with the Naga V3 Pro. Three magnetic side…

1 day ago

Surface Phone: New images show discarded Microsoft prototype

It's an open secret that Microsoft was working on a Windows Phone smartphone long before…

1 day ago

How Solar Carport Structures Are Changing the Future of Sustainable Energy Infrastructure

As the demand for renewable energy continues to grow, businesses, municipalities, and property owners are…

1 day ago

What to do to find the right family law support in your case.

Family law issues seldom come at an opportune moment. Divorce, separation, parenting conflicts, child support,…

1 day ago

Claude AI data leak: Private chats were freely accessible on Google

Due to an insufficiently protected sharing function, private chat logs from the Anthropic AI Claude…

2 days ago