vendor:
Windows Defender
by:
John Page (aka hyp3rlinx)
6.1
CVSS
HIGH
Detection Mitigation Bypass - Backdoor:JS/Relvelshe.A
937
CWE
Product Name: Windows Defender
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE: a:microsoft:windows_defender
Platforms Tested: Windows
2024
Windows Defender Backdoor Detection Mitigation Bypass
In 2022, a proof of concept was released to bypass the Backdoor:JS/Relvelshe.A detection in Windows Defender. Although the initial method was mitigated, a new approach involves adding a simple JavaScript try-catch error statement and evaluating the hex string to execute the bypass successfully.
Mitigation:
Ensure timely updates and patches from Microsoft for Windows Defender to address this detection mitigation bypass vulnerability.