{"id":537,"date":"2017-05-10T10:57:57","date_gmt":"2017-05-10T17:57:57","guid":{"rendered":"http:\/\/dshsolutions.com\/wordpress\/?p=537"},"modified":"2017-05-10T10:57:57","modified_gmt":"2017-05-10T17:57:57","slug":"microsoft-issues-emergency-patch-for-critical-rce-in-windows-malware-scanner","status":"publish","type":"post","link":"https:\/\/dshsolutions.com\/wordpress\/microsoft-issues-emergency-patch-for-critical-rce-in-windows-malware-scanner\/","title":{"rendered":"Microsoft Issues Emergency Patch For Critical RCE in Windows Malware Scanner"},"content":{"rendered":"<p>Make sure you get this Microsoft update asap.<\/p>\n<blockquote>\n<div id=\"aim11707587320568242362\">\n<div dir=\"ltr\">Microsoft&#8217;s own antivirus software made Windows 7, 8.1, RT and 10 computers, as well as Windows Server 2016 more vulnerable.<\/p>\n<p>Microsoft has just <a href=\"https:\/\/technet.microsoft.com\/en-us\/library\/security\/4022344.aspx\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">released<\/a> an out-of-band security update to patch the <a href=\"http:\/\/thehackernews.com\/2017\/05\/windows-rce-exploit.html\" target=\"_blank\" rel=\"noopener noreferrer\">crazy bad bug<\/a> discovered by a pair of Google Project Zero researchers over the weekend.<\/p>\n<p>Security researchers Tavis Ormandy announced on Twitter during the weekend that he and another Project Zero researcher Natalie Silvanovich discovered<i> &#8220;the worst Windows remote code [execution vulnerability] in recent memory.&#8221;<\/i><\/div>\n<\/div>\n<div id=\"insidearticlead\" class=\"clear\"><\/div>\n<div id=\"aim21707587320568242362\">\nNatalie Silvanovich also published a\u00a0<a href=\"https:\/\/twitter.com\/natashenka\/status\/861748397409058816\" target=\"_blank\" rel=\"noopener noreferrer\">proof-of-concept (PoC) exploit code<\/a> that fits in a single tweet.<\/p>\n<p>The <a href=\"http:\/\/thehackernews.com\/2017\/05\/windows-rce-exploit.html\" target=\"_blank\" rel=\"noopener noreferrer\">reported RCE vulnerability<\/a>, according to the duo, could work against default installations with <i>&#8220;wormable&#8221; <\/i>ability \u2013 capability to replicate itself on an infected computer and then spread to other PCs automatically.<\/p>\n<p>According to an <a href=\"https:\/\/technet.microsoft.com\/en-us\/library\/security\/4022344.aspx\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">advisory<\/a> released by Microsoft, the remotely exploitable security flaw (CVE-2017-0290) exists in <b>Microsoft Malware Protection Engine <\/b>(MMPE) \u2013 the company&#8217;s own antivirus engine that could be used to fully compromise Windows PCs without any user interaction.<\/div>\n<div><\/div>\n<div><a href=\"https:\/\/thehackernews.com\/2017\/05\/windows-defender-rce-flaw.html?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed%3A+TheHackersNews+%28The+Hackers+News+-+Security+Blog%29&amp;_m=3n.009a.1489.qm0ao08yu9.vye\">Read the article to see the list of affected software<\/a><\/div>\n<\/blockquote>\n<p>Source: <em><a href=\"https:\/\/thehackernews.com\/2017\/05\/windows-defender-rce-flaw.html?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed%3A+TheHackersNews+%28The+Hackers+News+-+Security+Blog%29&amp;_m=3n.009a.1489.qm0ao08yu9.vye\">Microsoft Issues Emergency Patch For Critical RCE in Windows Malware Scanner<\/a><\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Make sure you get this Microsoft update asap. Microsoft&#8217;s own antivirus software made Windows 7, 8.1, RT and 10 computers, as well as Windows Server 2016 more vulnerable. Microsoft has just released an out-of-band security update to patch the crazy bad bug discovered by a pair of Google Project Zero researchers over the weekend. Security [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[12,5],"tags":[],"class_list":["post-537","post","type-post","status-publish","format-standard","hentry","category-office-windows-powerpoint","category-security-2"],"_links":{"self":[{"href":"https:\/\/dshsolutions.com\/wordpress\/wp-json\/wp\/v2\/posts\/537","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/dshsolutions.com\/wordpress\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/dshsolutions.com\/wordpress\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/dshsolutions.com\/wordpress\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/dshsolutions.com\/wordpress\/wp-json\/wp\/v2\/comments?post=537"}],"version-history":[{"count":0,"href":"https:\/\/dshsolutions.com\/wordpress\/wp-json\/wp\/v2\/posts\/537\/revisions"}],"wp:attachment":[{"href":"https:\/\/dshsolutions.com\/wordpress\/wp-json\/wp\/v2\/media?parent=537"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/dshsolutions.com\/wordpress\/wp-json\/wp\/v2\/categories?post=537"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/dshsolutions.com\/wordpress\/wp-json\/wp\/v2\/tags?post=537"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}