QID 91880

Date Published: 2022-04-13

QID 91880: Microsoft Defender Denial of Service (DoS) Vulnerability for April 2022

A denial of service vulnerability exists when Microsoft Defender improperly handles files. An attacker could exploit the vulnerability to prevent legitimate accounts from executing legitimate system binaries.

Affected Products:
Microsoft System Center Endpoint Protection
Microsoft System Center 2012 R2 Endpoint Protection
Microsoft System Center 2012 Endpoint Protection
Microsoft Security Essentials.

QID Detection Logic (Authenticated):
The authenticated check looks for the version of mpengine.dll file.

Successful exploitation will cause Denial of Service attacks.

  • CVSS V3 rated as Medium - 5.5 severity.
  • CVSS V2 rated as Medium - 4.9 severity.
  • Solution
    Manually update the Microsoft Defender if It's not updated automatically.

    CVEs related to QID 91880

    Software Advisories
    Advisory ID Software Component Link
    CVE-2022-24548 URL Logo msrc.microsoft.com/update-guide/vulnerability/CVE-2022-24548