CVE-2021-42298
published 2021-11-10CVE-2021-42298: Microsoft Defender Remote Code Execution Vulnerability
PriorityP277high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
ITWVulnCheck KEV
Exploited in the wild
EPSS
5.29%
91.7th percentile
Microsoft Defender Remote Code Execution Vulnerability
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | malware_protection_engine | < 1.1.18700.3 | 1.1.18700.3 |
| microsoft | microsoft_malware_protection_engine | >= 1.1.0.0 < 1.1.18700.3 | 1.1.18700.3 |
| msrc | microsoft_malware_protection_engine | — | — |
Detection & IOCsextracted from sources · hover to see the quote
snort↗
58519
snort↗
58520
snort↗
58539
snort↗
58540
snort↗
58541
snort↗
300054
- →Check Microsoft Malware Protection Engine version on endpoints; any version below 1.1.18700.3 is vulnerable. Systems with Defender disabled are NOT in an exploitable state despite binaries remaining on disk. ↗
- →Vulnerability scanners may false-positive on disabled Defender installs; confirm exploitability only when Defender is active. ↗
- →CVE-2021-42298 is reportedly exploited by the 'Varison' threat group; threat-hunt for this group's TTPs on Windows endpoints running unpatched Defender. ↗
- ·Affected component is Microsoft Malware Protection Engine (mpengine.dll); all products using this engine are affected, including Microsoft Defender, System Center Endpoint Protection, and Microsoft Security Essentials. ↗
- ·The patch is delivered automatically via antimalware definition/engine update channels; no manual OS patch is required, but enterprise admins must confirm auto-update pipelines are functioning. ↗
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vulncheck7.8HIGH
vendor_msrc7.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Microsoft Defender Remote Code Execution Vulnerability
vendor_msrc·2021-11-09·CVSS 7.8
CVE-2021-42298 [HIGH] Microsoft Defender Remote Code Execution Vulnerability
Microsoft Defender Remote Code Execution Vulnerability
FAQ:
References
Identification
First version of the Microsoft Malware Protection Engine with this vulnerability addressed
Version 1.1.18700.3
See Manage Updates Baselines Microsoft Defender Antivirus for more information.
Microsoft Defender is disabled in my environment, why are vulnerability scanners showing that I am vulnerable to this issue?
Vulnerability scanners are looking for specific binaries and version numbers on devices. Microsoft Defender files are still on disk even when disabled. Systems that have disabled Microsoft Defender are not in an exploitable state.
Why is no action required to install this update?
In response to a constantly changing threat landscape, Microsoft frequently updates malware definitions and th
GHSA
GHSA-hrr5-6mf9-3wxh: Microsoft Defender Remote Code Execution Vulnerability
ghsa_unreviewed·2022-05-24
CVE-2021-42298 [HIGH] CWE-94 GHSA-hrr5-6mf9-3wxh: Microsoft Defender Remote Code Execution Vulnerability
Microsoft Defender Remote Code Execution Vulnerability
VulnCheck
Microsoft Malware Protection Engine Improper Control of Generation of Code ('Code Injection')
vulncheck·2021·CVSS 7.8
CVE-2021-42298 [HIGH] Microsoft Malware Protection Engine Improper Control of Generation of Code ('Code Injection')
Microsoft Malware Protection Engine Improper Control of Generation of Code ('Code Injection')
Microsoft Defender Remote Code Execution Vulnerability
Affected: Microsoft Malware Protection Engine
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://blog.google/threat-analysis-group/new-details-on-commercial-spyware-vendor-variston/
No detection rules found.
No public exploits indexed.
Qualys
Part 1: An In-Depth Look at the Latest Vulnerability Threat Landscape
blogs_qualys·2023-07-11
Part 1: An In-Depth Look at the Latest Vulnerability Threat Landscape
## Table of Contents
Access Vector: Network vs Local
Authentication/Privilege Required to Exploiting the Vulnerability
Common Weakness Exploited by High-Risk Vulnerabilities
High-Risk Vulnerabilities Vs MITRE ATT&CK Framework
High-Risk Vulns Vs CISA Known Exploited Vulns (CISA KEV)
Exploit Prediction Scoring System (EPSS) for Vulnerabilities with Weaponized Exploits
Risk-Based Prioritization with Qualys VMDR with TruRisk
Key Insights & Takeaways:
References
Additional Contributor
The number of vulnerabilities is steadily increasing over the years, as evidenced by the 206,000 vulnerabilities reported and still counting in the National Vulnerability Database (NVD). With each subsequent year, this trend has persisted since 2016, surpassing the previous vulnerability count. In 2023
Qualys
Part 1: An In-Depth Look at the Latest Vulnerability Threat Landscape | Qualys
blogs_qualys·2023-07-11
Part 1: An In-Depth Look at the Latest Vulnerability Threat Landscape | Qualys
#### Table of Contents
- Access Vector: Network vs Local
- Authentication/Privilege Required to Exploiting the Vulnerability
- Common Weakness Exploited by High-Risk Vulnerabilities
- High-Risk Vulnerabilities Vs MITRE ATT&CK Framework
- High-Risk Vulns Vs CISA Known Exploited Vulns (CISA KEV)
- Exploit Prediction Scoring System (EPSS) for Vulnerabilities with Weaponized Exploits
- Risk-Based Prioritization with Qualys VMDR with TruRisk
- Key Insights & Takeaways:
- References
- Additional Contributor
The number of vulnerabilities is steadily increasing over the years, as evidenced by the 206,000 vulnerabilities reported and still counting in the National Vulnerability Database (NVD). With each subsequent year, this trend has persisted since 2016, surpassing the previous vulnerability co
Wiz
5 reasons endpoint security agents are not enough | Wiz Blog
blogs_wiz·2022-02-03
5 reasons endpoint security agents are not enough | Wiz Blog
Agents have always been an inherent part of security and operations, finding a place in vulnerability scanning, threat detection, data loss prevention (DLP), remote management, virtual private networks (VPN), and more. We all know them, we all have them, and as a result, we are all faced with the burden of managing, deploying, and updating countless endpoint agents. In the cloud, this becomes even more complex since IT teams do not necessarily have control over all the deployed workloads, leading to an endless cat-and-mouse game of trying to get developers to deploy the various agents.
In this post, we discuss five security limitations of endpoint security agents: lack of coverage, deployment difficulties, an increased attack surface, susceptible high privileges, and ease of avoidance by
Qualys
Microsoft & Adobe Patch Tuesday (November 2021) – Microsoft 55 Vulnerabilities with 6 Critical, 6 Zero-Days. Adobe 4 Vulnerabilities | Qualys
blogs_qualys·2021-11-11·CVSS 9.0
CVE-2021-42298 [CRITICAL] Microsoft & Adobe Patch Tuesday (November 2021) – Microsoft 55 Vulnerabilities with 6 Critical, 6 Zero-Days. Adobe 4 Vulnerabilities | Qualys
#### Table of Contents
- Microsoft Patch Tuesday November 2021
- Adobe Patch Tuesday October 2021
- Discover Patch Tuesday Vulnerabilities in VMDR
- Respond by Patching
- Patch Tuesday Dashboard
- About Patch Tuesday
## Microsoft Patch Tuesday – November 2021
Microsoft patched 55 vulnerabilities in their November 2021 Patch Tuesday release, of which six are rated as critical severity and six were previously reported as zero-days.
### Critical Microsoft Vulnerabilities Patched
CVE-2021-42298 – Microsoft Defender Remote Code Execution Vulnerability
This vulnerability in Microsoft Defender can be exploited using Maliciously crafted files. The remote code execution vulnerability will be triggered when the malicious file is opened by a user or scanned automatically via an outdated version
Qualys
Microsoft & Adobe Patch Tuesday (November 2021) – Microsoft 55 Vulnerabilities with 6 Critical, 6 Zero-Days. Adobe 4 Vulnerabilities
blogs_qualys·2021-11-11·CVSS 9.0
CVE-2021-42298 [CRITICAL] Microsoft & Adobe Patch Tuesday (November 2021) – Microsoft 55 Vulnerabilities with 6 Critical, 6 Zero-Days. Adobe 4 Vulnerabilities
## Table of Contents
Microsoft Patch Tuesday November 2021
Adobe Patch Tuesday October 2021
Discover Patch Tuesday Vulnerabilities in VMDR
Respond by Patching
Patch Tuesday Dashboard
About Patch Tuesday
## Microsoft Patch Tuesday – November 2021
Microsoft patched 55 vulnerabilities in their November 2021 Patch Tuesday release, of which six are rated as critical severity and six were previously reported as zero-days.
## Critical Microsoft Vulnerabilities Patched
CVE-2021-42298 – Microsoft Defender Remote Code Execution Vulnerability
This vulnerability in Microsoft Defender can be exploited using Maliciously crafted files. The remote code execution vulnerability will be triggered when the malicious file is opened by a user or scanned automatically via an outdated version of Micros
Trendmicro
November Continues Streak of Quiet Patch Tuesdays
blogs_trendmicro·2021-11-10·CVSS 9.0
[CRITICAL] November Continues Streak of Quiet Patch Tuesdays
Ausnutzung von Schwachstellen
## November Continues Streak of Quiet Patch Tuesdays
November continues a recent pattern of relatively peaceful Patch Tuesday cycles. There were only six vulnerabilities rated as Critical this month, with 49 more rated as Important for a total of 55 for the month of November.
By: Trend Micro Nov 10, 2021 Read time: ( words)
Save to Folio
November continues a recent pattern of relatively peaceful Patch Tuesday cycles. There were only six vulnerabilities rated as Critical this month, with 49 more rated as Important for a total of 55 for the month of November (less than half of the vulnerabilities in November last year). Of these 55, four were submitted via the Zero Day Initiative (ZDI).
Critical Vulnerabilities: Defender, Remote Desktop
Two Critical vulne
Trendmicro
November Continues Streak of Quiet Patch Tuesdays
blogs_trendmicro·2021-11-10·CVSS 9.0
[CRITICAL] November Continues Streak of Quiet Patch Tuesdays
Exploits y vulnerabilidades
## November Continues Streak of Quiet Patch Tuesdays
November continues a recent pattern of relatively peaceful Patch Tuesday cycles. There were only six vulnerabilities rated as Critical this month, with 49 more rated as Important for a total of 55 for the month of November.
By: Trend Micro Nov 10, 2021 Read time: ( words)
Save to Folio
November continues a recent pattern of relatively peaceful Patch Tuesday cycles. There were only six vulnerabilities rated as Critical this month, with 49 more rated as Important for a total of 55 for the month of November (less than half of the vulnerabilities in November last year). Of these 55, four were submitted via the Zero Day Initiative (ZDI).
Critical Vulnerabilities: Defender, Remote Desktop
Two Critical vulnera
Trendmicro
November Continues Streak of Quiet Patch Tuesdays
blogs_trendmicro·2021-11-10·CVSS 9.0
[CRITICAL] November Continues Streak of Quiet Patch Tuesdays
Exploits & Vulnerabilities
## November Continues Streak of Quiet Patch Tuesdays
November continues a recent pattern of relatively peaceful Patch Tuesday cycles. There were only six vulnerabilities rated as Critical this month, with 49 more rated as Important for a total of 55 for the month of November.
By: Trend Micro Nov 10, 2021 Read time: ( words)
Save to Folio
November continues a recent pattern of relatively peaceful Patch Tuesday cycles. There were only six vulnerabilities rated as Critical this month, with 49 more rated as Important for a total of 55 for the month of November (less than half of the vulnerabilities in November last year). Of these 55, four were submitted via the Zero Day Initiative (ZDI).
Critical Vulnerabilities: Defender, Remote Desktop
Two Critical vulnerab
Trendmicro
November Continues Streak of Quiet Patch Tuesdays
blogs_trendmicro·2021-11-10·CVSS 9.0
[CRITICAL] November Continues Streak of Quiet Patch Tuesdays
Exploits & Vulnerabilities
## November Continues Streak of Quiet Patch Tuesdays
November continues a recent pattern of relatively peaceful Patch Tuesday cycles. There were only six vulnerabilities rated as Critical this month, with 49 more rated as Important for a total of 55 for the month of November.
By: Trend Micro 2021/11/10 Read time: ( words)
Save to Folio
November continues a recent pattern of relatively peaceful Patch Tuesday cycles. There were only six vulnerabilities rated as Critical this month, with 49 more rated as Important for a total of 55 for the month of November (less than half of the vulnerabilities in November last year). Of these 55, four were submitted via the Zero Day Initiative (ZDI).
Critical Vulnerabilities: Defender, Remote Desktop
Two Critical vulnerabil
Trendmicro
November Continues Streak of Quiet Patch Tuesdays
blogs_trendmicro·2021-11-10·CVSS 9.0
[CRITICAL] November Continues Streak of Quiet Patch Tuesdays
Exploits & Vulnerabilities
# November Continues Streak of Quiet Patch Tuesdays
November continues a recent pattern of relatively peaceful Patch Tuesday cycles. There were only six vulnerabilities rated as Critical this month, with 49 more rated as Important for a total of 55 for the month of November.
By: Trend Micro
2021/11/10
Read time: ( words)
Save to Folio
November continues a recent pattern of relatively peaceful Patch Tuesday cycles. There were only six vulnerabilities rated as Critical this month, with 49 more rated as Important for a total of 55 for the month of November (less than half of the vulnerabilities in November last year). Of these 55, four were submitted via the Zero Day Initiative (ZDI).
Critical Vulnerabilities: Defender, Remote Desktop
Two Critical vulnerabil
Trendmicro
November Continues Streak of Quiet Patch Tuesdays
blogs_trendmicro·2021-11-10·CVSS 9.0
[CRITICAL] November Continues Streak of Quiet Patch Tuesdays
Sfruttamento vulnerabilità
## November Continues Streak of Quiet Patch Tuesdays
November continues a recent pattern of relatively peaceful Patch Tuesday cycles. There were only six vulnerabilities rated as Critical this month, with 49 more rated as Important for a total of 55 for the month of November.
By: Trend Micro Nov 10, 2021 Read time: ( words)
Save to Folio
November continues a recent pattern of relatively peaceful Patch Tuesday cycles. There were only six vulnerabilities rated as Critical this month, with 49 more rated as Important for a total of 55 for the month of November (less than half of the vulnerabilities in November last year). Of these 55, four were submitted via the Zero Day Initiative (ZDI).
Critical Vulnerabilities: Defender, Remote Desktop
Two Critical vulnerab
Talos
Microsoft Patch Tuesday for Nov. 2021 — Snort rules and prominent vulnerabilities
blogs_talos·2021-11-09·CVSS 8.8
CVE-2021-42292 [HIGH] Microsoft Patch Tuesday for Nov. 2021 — Snort rules and prominent vulnerabilities
By Jon Munshaw and Tiago Pereira.
Microsoft released its monthly security update Tuesday, disclosing 56 vulnerabilities in the company’s various software, hardware and firmware offerings, including one that’s actively being exploited in the wild.
November’s security update features six critical vulnerabilities, up from last month’s two, which was far lower than average for Microsoft. The other 50 vulnerabilities fixed today are considered “important.”
CVE-2021-42292 is one of those vulnerabilities considered “important” and not critical, though it is the only one included in this security update that Microsoft reports has been spotted being exploited in the wild. An attacker could exploit this vulnerability in Microsoft Excel to bypass certain security settings on targeted machines.
In
Talos
Microsoft Patch Tuesday for Nov. 2021 — Snort rules and prominent vulnerabilities
blogs_talos·2021-11-09·CVSS 8.8
[HIGH] Microsoft Patch Tuesday for Nov. 2021 — Snort rules and prominent vulnerabilities
## Microsoft Patch Tuesday for Nov. 2021 — Snort rules and prominent vulnerabilities
By Jon Munshaw and Tiago Pereira.
Microsoft released its monthly security update Tuesday, disclosing 56 vulnerabilities in the company’s various software, hardware and firmware offerings, including one that’s actively being exploited in the wild.
November’s security update features six critical vulnerabilities, up from last month’s two, which was far lower than average for Microsoft. The other 50 vulnerabilities fixed today are considered “important.”
CVE-2021-42292 is one of those vulnerabilities considered “important” and not critical, though it is the only one included in this security update that Microsoft reports has been spotted being exploited in the wild. An attacker could exploit this vulnerab
Crowdstrike
November 2021 Patch Tuesday: Updates and Analysis
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] November 2021 Patch Tuesday: Updates and Analysis
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand ATT&CK in 10 Minutes or Less [VI
Crowdstrike
November 2021 Patch Tuesday: Updates and Analysis
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] November 2021 Patch Tuesday: Updates and Analysis
How CrowdStrike is Accelerating Exposure Evaluation as Adversaries Gain Speed Apr 06, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How CrowdStrike is Accelerating Exposure Evaluation as Adversaries Gain Speed Apr 06, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand AT
Zscaler
Zscaler found Windows Security Vulnerabilities | 11-09-2021
blogs_zscaler·CVSS 7.8
[HIGH] Zscaler found Windows Security Vulnerabilities | 11-09-2021
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
2021-11-10
Published
Exploited in the wild