vendor:
Windows Defender
by:
John Page (hyp3rlinx)
6.1
CVSS
HIGH
Detection Mitigation Bypass
119
CWE
Product Name: Windows Defender
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: NO
Related CWE:
CPE: o:microsoft:windows_defender
Platforms Tested: Windows
2024
Windows Defender Detection Mitigation Bypass for Backdoor:JS/Relvelshe.A
In 2022, a Proof of Concept (PoC) was released to bypass the detection of Backdoor:JS/Relvelshe.A in Windows Defender, which was later mitigated. However, by adding a simple JavaScript try-catch error statement and evaluating the hex string, the bypass can still be achieved.
Mitigation:
Ensure to keep Windows Defender up to date with the latest security patches to prevent this detection mitigation bypass.