vendor:
Windows Defender
by:
John Page (aka hyp3rlinx)
6.1
CVSS
HIGH
Windows Defender Detection Mitigation Bypass - TrojanWin32Powessere.G
20
CWE
Product Name: Windows Defender
Affected Version From: Not specified
Affected Version To: Not specified
Patch Exists: NO
Related CWE:
CPE: o:microsoft:windows_defender
Platforms Tested: Windows
2024
Windows Defender Trojan.Win32Powessere.G Mitigation Bypass
Windows Defender usually prevents the execution of TrojanWin32Powessere.G by leveraging rundll32.exe. However, by using multiple commas in the execution command, the mitigation can be bypassed, allowing successful execution of the trojan.
Mitigation:
Ensure timely updates and patches from Microsoft. Exercise caution when running unknown scripts or commands.