Executive brief
Microsoft Defender contains a remote code execution vulnerability due to improper handling of files. While classified as RCE, the attack vector is local, requiring an attacker to have basic user privileges to execute the exploit. This vulnerability was confirmed to be exploited in the wild.
Affected products
- Microsoft Microsoft Defender All versions on supported Windows OS
Timeline
- 2021-11-03: disclosed
- 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2021-11-03: patched