QID 92079

Date Published: 2023-11-15

QID 92079: Microsoft Windows Defender Elevation of Privilege Vulnerability for November 2023

Microsoft Defender Antivirus (formerly Windows Defender) is an antivirus software component of Microsoft Windows.

Successful exploitation of this vulnerability could allow a local attacker to execute code with SYSTEM privileges.

Affected Software:
Microsoft Malware Protection Engine version prior to Version 1.1.23100.2009

QID Detection Logic (Authenticated):
This authenticated detection checks if the "mpengine.dll" file version is lesser than 1.1.23100.2009.

A local attacker who successfully exploited this vulnerability could gain SYSTEM privileges.

  • CVSS V3 rated as Low - 0 severity.
  • CVSS V2 rated as High - 6.8 severity.
  • Solution
    Customers are advised to follow CVE-2023-36422 for more information.

    CVEs related to QID 92079

    Software Advisories
    Advisory ID Software Component Link
    CVE-2023-36422 URL Logo msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36422