Microsoft modifies open-source code, blows hole in Windows Defender

By Shaun Nichols

A remote-code execution vulnerability in Windows Defender – a flaw that can be exploited by malicious .rar files to run malware on PCs – has been traced back to an open-source archiving tool Microsoft adopted for its own use.

The bug, CVE-2018-0986, was patched on Tuesday in the latest version of the Microsoft Malware Protection Engine (1.1.14700.5) in Windows Defender, Security Essentials, Exchange Server, Forefront Endpoint Protection, and Intune Endpoint Protection.

To read the entire article, please click here.

Source:http://www.theregister.co.uk/

Facebooktwittergoogle_plusredditlinkedinmail