CVE-2021-1647KEV · OVERDUE

Microsoft Defender Remote Code Execution Vulnerability

High · published January 12, 2021

Patch now

Confirmed exploited, and the score agrees

CVSS calls it high at 7.8. It is confirmed in active exploitation. It sits in the 98.5th percentile for exploit probability.

1754
days past CISA
deadline
CVSS v3.1
7.8
EPSS
39%
Percentile
98.5
In the wild
Confirmed
What it is

🚨 A misconfiguration in Microsoft Defender allows attackers to execute code remotely with just a sneaky trick! ⚡ This is like a hotel receptionist who doesn’t check IDs before giving out keys. If someone walks in with a convincing story, they could access any room – or in this case, your system. 🏨 An attacker could gain complete control over the system, enabling them to run malicious programs, steal sensitive data, or wreak havoc at will. It's absolutely devastating, as users could wake up to find their data manipulated or stolen overnight!

Put simply

This is like a hotel receptionist who doesn’t check IDs before giving out keys. If someone walks in with a convincing story, they could access any room – or in this case, your system. 🏨 This vulnerability arises from improper validation in Microsoft Defender, allowing remote code execution when the software processes malicious inputs.

What to do

An attacker could gain complete control over the system, enabling them to run malicious programs, steal sensitive data, or wreak havoc at will. It's absolutely devastating, as users could wake up to find their data manipulated or stolen overnight! Patch your Microsoft Defender to the latest version immediately to close this loophole. Review your security configurations to ensure only validated inputs are permitted, and monitor your systems for any suspicious activity. 🛡️ You’ve got this! With these steps, you can secure your system and keep those sneaky attackers at bay! 🔒

The record
Technical detail
CVSS v3.1
7.8 · HIGH
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C
CVSS v4.0
Not supplied
EPSS
0.39392 · 98.5th percentile
Published
2021-01-12T19:42Z
KEV added
2021-11-03 · due 2021-11-17
EPSS history
Timeline
  • 03 NOV 00:00Z
    Added to CISA KEV — remediate by Nov 17
    kev
  • 12 JAN 19:42Z
    Microsoft Defender Remote Code Execution Vulnerability
    cvelistv5