Junglewise Threat Intelligence

CVE-2021-1647: Microsoft Defender Remote Code Execution Vulnerability

CVE-2021-1647 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2021-11-03

Technologies: Microsoft Defender. Vendors: Microsoft.

Executive brief

Microsoft Defender contains a remote code execution vulnerability due to improper handling of files. While classified as RCE, the attack vector is local, requiring an attacker to have basic user privileges to execute the exploit. This vulnerability was confirmed to be exploited in the wild.

Affected products

  • Microsoft Microsoft Defender All versions on supported Windows OS

Timeline

  • 2021-11-03: disclosed
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2021-11-03: patched

Related threats