SB2019121027 - Security feature bypass in Microsoft Defender



SB2019121027 - Security feature bypass in Microsoft Defender

Published: December 10, 2019

Security Bulletin ID SB2019121027
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Data manipulation

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Security Features (CVE-ID: CVE-2019-1488)

The vulnerability allows a local user to bypass security features on the target system.

The vulnerability exists due to the Microsoft Defender improperly handles specific buffers. A local user can trigger warnings and false positives when no threat is present.

To exploit the vulnerability, an attacker would first require execution permissions on the victim system.

Remediation

Install update from vendor's website.