Microsoft Defender
cpe:2.3:a:microsoft:windows_defender:*:*:*:*:*:*:*
- 1.1.26030.3008
A heap-based buffer overflow vulnerability has been identified in Microsoft Defender. This vulnerability allows an unauthorized attacker to execute code remotely over a network. It affects all supported versions of Windows where Microsoft Defender is installed and active by default. The vulnerability arises from the Microsoft Malware Protection Engine, which provides scanning, detection, and cleaning capabilities for Microsoft antivirus and antispyware software.
Exploitation of this vulnerability could lead to remote code execution on the affected system.
The vulnerability has been addressed in version 1.1.26040.8 of the Microsoft Malware Protection Engine. Instructions for managing updates in Microsoft Defender Antivirus can be found in the Microsoft Defender Antivirus Update Management documentation.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.