vendor:
Windows Defender
by:
John Page (hyp3rlinx)
6.1
CVSS
HIGH
Windows Defender Detection Mitigation Bypass - TrojanWin32Powessere.G
119
CWE
Product Name: Windows Defender
Affected Version From: Windows Defender
Affected Version To: Windows Defender
Patch Exists: NO
Related CWE:
CPE: a:microsoft:windows_defender
Platforms Tested: Windows
2024
Windows Defender TrojanWin32Powessere.G Mitigation Bypass Part 2
Windows Defender typically prevents execution of TrojanWin32Powessere.G by leveraging rundll32.exe, resulting in 'Access is denied' error. A mitigation bypass was disclosed in 2022 involving mshtml reference traversal. However, using multiple commas bypasses this mitigation, allowing successful execution.
Mitigation:
Ensure system and Windows Defender definitions are updated regularly to detect and prevent such bypass attempts.