QID 91994

Date Published: 2023-03-16

QID 91994: Microsoft Defender Elevation of Privilege Vulnerability for March 2023

Microsoft Defender for Endpoint is an enterprise endpoint security platform designed to help enterprise networks prevent, detect, investigate, and respond to advanced threats.

Affected Software:
Microsoft Malware Protection Engine

QID Detection Logic (Authenticated):
The authenticated check looks for the version of mpengine.dll file, if the version is less than 1.1.20000.2, it is considered as vulnerable.

Successful exploitation could allow an attacker to delete data that could include data that results in the service being unavailable.

  • CVSS V3 rated as High - 6.3 severity.
  • CVSS V2 rated as Medium - 4.6 severity.
  • Solution
    Customers are advised to refer to CVE-2023-23389 for more information pertaining to this vulnerability.

    CVEs related to QID 91994

    Software Advisories
    Advisory ID Software Component Link
    CVE-2023-23389 URL Logo msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2023-23389