vendor:
Windows Defender
by:
John Page (aka hyp3rlinx)
4.1
CVSS
MEDIUM
Mitigation bypass in Windows Defender for TrojanWin32Powessere.G using VBScript
284
CWE
Product Name: Windows Defender
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE: o:microsoft:windows
Platforms Tested: Windows
2021
Windows Defender VBScript Detection Mitigation Bypass for TrojanWin32Powessere.G
Windows Defender normally detects and prevents the execution of TrojanWin32Powessere.G which leverages rundll32.exe. By using a VBScript and ActiveX engine, attackers can bypass the detection. Running a specific command can allow the execution of arbitrary commands from an attacker. This bypass involves adding arbitrary text to a parameter, such as 'shtml' or 'Lol', to evade Windows Defender detection.
Mitigation:
Ensure to keep Windows Defender definitions up to date and consider using additional security solutions to enhance protection against such bypass techniques.