vendor:
Windows Defender
by:
John Page (aka hyp3rlinx)
6.1
CVSS
HIGH
Windows Defender Detection Mitigation Bypass - TrojanWin32Powessere.G
287
CWE
Product Name: Windows Defender
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: YES
Related CWE:
CPE: o:microsoft:windows_defender
Platforms Tested: Windows
2024
Microsoft Windows Defender TrojanWin32Powessere.G Mitigation Bypass Part 3
Windows Defender fails to detect and prevent execution of TrojanWin32Powessere.G when leveraging rundll32.exe, leading to an 'Access is denied' error. The bypass was first disclosed in 2022 by passing an extra path traversal with mshtml, which was later mitigated. Subsequently, on Feb 7, 2024, using multiple commas as part of the path allowed bypassing the mitigation until it was fixed. Another trivial bypass was discovered soon after.
Mitigation:
Ensure Windows Defender is kept up to date with the latest security patches to prevent the described bypass techniques.