⚠ Actively exploited
Added to CISA KEV on 2021-11-03. Federal agencies required to patch by 2021-11-17. Required action: Apply updates per vendor instructions..
Severity
7.8HIGH
EPSS
77.4%
top 1.02%
CISA KEV
KEV
Added 2021-11-03
Due 2021-11-17
Exploit
Exploited in wild
Active exploitation observed
Timeline
PublishedJan 12
KEV addedNov 3
KEV dueNov 17
Latest updateMay 24
CISA Required Action: Apply updates per vendor instructions.

Description

Microsoft Defender Remote Code Execution Vulnerability

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Patches

🔴Vulnerability Details

4
GHSA
GHSA-4v4q-r2mh-q7w6: Microsoft Defender Remote Code Execution Vulnerability2022-05-24
CVEList
Microsoft Defender Remote Code Execution Vulnerability2021-01-12
VulnCheck
Microsoft Defender Remote Code Execution Vulnerability2021
Project0
Project Zero RCA: CVE-2021-1647: Windows Defender mpengine remote code execution

📋Vendor Advisories

2
CISA
Microsoft Defender Remote Code Execution Vulnerability2021-11-03
Microsoft
Microsoft Defender Remote Code Execution Vulnerability2021-01-12

🕵️Threat Intelligence

1
Krebs
Microsoft Patch Tuesday, January 2021 Edition2021-01-13
CVE-2021-1647 (HIGH CVSS 7.8) | Microsoft Defender Remote Code Exec | cvebase.io