Install February 2022 Defender Security Intelligence and Product updates to fix the Microsoft Defender AV Scan Bypass Weakness

Microsoft have recently addressed a weakness in the Microsoft Defender Antivirus exclusion feature on Windows that could allow attackers to bypass Defender detection altogether. 

The weakness was found to be in the registry 'HKLM\Software\Microsoft\Windows Defender\Exclusions' that supposedly had access to 'Everyone' group. Obviously, this is really bad because the key contains the list of locations (files, folders, extensions, or processes) excluded from Microsoft Defender scanning. Not only the attackers could exploit this remotely, it also made possible for local users (regardless of their permissions) to access it via the command line by querying the Windows Registry.

Luckily, it seems that the issue has been fixed after February'22 updates. I verified in my test lab and the permissions seem to be correct now. I cannot see 'Everyone' group given access anymore on a Windows 10 21H2 device.


Now when it comes to the actual updates, Microsoft Defender is kept up to date using Security intelligence and Product updates. While Security intelligence updates are delivered through cloud-delivered protection (also called the Microsoft Advanced Protection Service or MAPS), Product updates on the other hand are delivered through monthly updates. It is critical to install these updates as soon as they are released to ensure that you have the latest technology and features running in order to protect against new malware and attack techniques.

If you are managing Windows 10\11 devices using Intune, then you can configure and enable these updates easily.

In order to enable Security Intelligence Updates, make sure to enable the following settings under Endpoint security > Antivirus Profile, as shown below.


You have the option to configure these settings using Defender Baseline or Device restriction profile in Intune, but I recommend using Endpoint Security profile as these are more aligned with Device security settings.

The next step is to ensure that you have Update ring configured to push down the monthly security updates. Now you can have your own schedule to suit your requirements, or use the settings below as a point of reference.


To put matters into perspective, at the time of writing this blog, these are the recent updates made available by Microsoft.

 Security intelligence update version: 1.359.64.0
 Released: February 9, 2022
 Platform: 4.18.2201.10
 Engine: 1.1.18900.3

Once installed, you can verify it in the Intune Defender AV report as shown below.


Can also be verified locally on the machine.


That is it for now. Just remember that as long as relevant security updates are being pushed out, you can ensure that devices in your environment stay secured. Until next time..

Comments

Popular posts from this blog

How to force escrowing of BitLocker recovery keys using Intune

Intune: Configure Printers for Non-Administrative Users

Prevent users from running certain programs or applications on Windows endpoints using Intune