Install February 2022 Defender Security Intelligence and Product updates to fix the Microsoft Defender AV Scan Bypass Weakness
Microsoft have recently addressed a weakness in the Microsoft Defender Antivirus exclusion feature on Windows that could allow attackers to bypass Defender detection altogether. The weakness was found to be in the registry ' HKLM\Software\Microsoft\Windows Defender\Exclusions' that supposedly had access to 'Everyone ' group. Obviously, this is really bad because the key contains the list of locations (files, folders, extensions, or processes) excluded from Microsoft Defender scanning. Not only the attackers could exploit this remotely, it also made possible for local users (regardless of their permissions) to access it via the command line by querying the Windows Registry. Luckily, it seems that the issue has been fixed after February'22 updates. I verified in my test lab and the permissions seem to be correct now. I cannot see 'Everyone ' group given access anymore on a Windows 10 21H2 device. Now when it comes to the actual updates, Microsoft Defender ...