Microsoft just fixed a serious Windows Defender bug

Over the weekend, Google Project Zero researchers Tavis Ormandy and Natalie Silvanovich tweeted about discovering “the worst Windows remote code exec in recent memory.” According to Ormandy, it could work against a default installation and even become “wormable” — able to replicate itself on a targeted machine and then spread to other computers automatically. Now we know more about what the problem is since, in just two days, Microsoft’s Security Response Center and Windows Defender developers were able to come up with a fix that is now available via Windows Update for Windows 7, 8.1, RT and 10, among others.

As described by the Project Zero team, the problem resided in Microsoft’s antimalware protection engine, which is supposed to scan files for issues, but could be tricked into executing code included in an email, on a webpage or in an instant message. Now that it’s patched, your Windows computer should download the updated version automatically within the next day or two.

Windows Defender

If you’re in a hurry, you can punch the update button and get it manually, likely without a reboot — just check your Windows Defender settings to make sure it has an engine listed with version 1.1.13704.0 or higher.

Source: Google Project Zero, Microsoft Security Advisory

Source: Engadget - Read the full article here

Author: Daily Tech Whip

This article is part of our 'News Tiles' service. The site is currently in Beta. When it is fully operational you will be able to search through and arrange the 'Tiles' to display a keyword, product or technology over your chosen time period. For example you would be able to display all of the leading tech articles on the new Kindle Fire, in one spot in real time. You will also have access to our own original reporting and analysis as well as a polished place to post your own thoughts & reviews here, amongst the Daily Tech Whip Community. Please let us know if you have any feedback via the contact form or via Twitter. Don't forget to come back next week and see our full site and claim your name and your own free tech blog.

Share This Post On