Security News > 2021 > January > Critical Microsoft Defender Bug Actively Exploited; Patch Tuesday Offers 83 Fixes

Critical Microsoft Defender Bug Actively Exploited; Patch Tuesday Offers 83 Fixes
2021-01-12 21:45

Microsoft addressed 10 critical bugs, one under active exploit and another publicly known, in its January Patch Tuesday roundup of fixes.

The most serious bug is a flaw in Microsoft's Defender anti-malware software that allows remote attackers to infect targeted systems with executable code.

Last month, Microsoft said state-sponsored hackers had compromised its internal network and leveraged additional Microsoft products to conduct further attacks.

"The previous patch introduced a function to check an input string pointer, but in doing so, it introduced an Out-of-Bounds Read condition. Additional bugs are also covered by this patch, including an untrusted pointer deref," Childs wrote in a prepared Patch Tuesday analysis.

Eight additional bugs rated critical were also part of Microsoft's Tuesday vulnerability fixes.

Five January Patch Tuesday flaws were each remote procedure call bugs.


News URL

https://threatpost.com/critical-microsoft-defender-bug-exploited/162992/

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Microsoft 725 810 4735 4736 3649 13930