QID 91880
Date Published: 2022-04-13
QID 91880: Microsoft Defender Denial of Service (DoS) Vulnerability for April 2022
A denial of service vulnerability exists when Microsoft Defender improperly handles files. An attacker could exploit the vulnerability to prevent legitimate accounts from executing legitimate system binaries.
Affected Products:
Microsoft System Center Endpoint Protection
Microsoft System Center 2012 R2 Endpoint Protection
Microsoft System Center 2012 Endpoint Protection
Microsoft Security Essentials.
QID Detection Logic (Authenticated):
The authenticated check looks for the version of mpengine.dll file.
Successful exploitation will cause Denial of Service attacks.
Solution
Manually update the Microsoft Defender if It's not updated automatically.
Vendor References
- CVE-2022-24548 -
msrc.microsoft.com/update-guide/vulnerability/CVE-2022-24548
CVEs related to QID 91880
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2022-24548 |
|