Massive vulnerability in Windows Defender leaves most Windows PCs vulnerable
Article Link: https://arstechnica.com/information...indows-defender-nscript-remote-vulnerability/
Article Link: https://arstechnica.com/information...indows-defender-nscript-remote-vulnerability/
Microsoft on Monday patched a severe code-execution vulnerability in the malware protection engine that is used in almost every recent version of Windows (7, 8, 8.1, 10, and Server 2016), just three days after it came to its attention.
The exploit (officially dubbed CVE-2017-0290) allows a remote attacker to take over a system without any interaction from the system owner: it's simply enough for the attacker to send an e-mail or instant message that is scanned by Windows Defender.