British spooks find hole in Microsoft Defender and Security Essentials

@ 2017/12/11
Vole rushes to patch

Microsoft has posted an out-of-band security update to fix a remote code execution flaw in its Malware Protection Engine.

The flaw, CVE-2017-11937, has not yet been exploited yet but it is a real doozy.

The security hole is present in Windows Defender and Microsoft Security Essentials, as well as Endpoint Protection, Forefront Endpoint Protection, and Exchange Server 2013 and 2016.

It was discovered and reported by the UK's National Cyber Security Centre – which is part of GCHQ, Blighty's spying nerve centre.

No comments available.