Windows Defender vulnerability finally patched after 12 years

Windows defender logo
(Image credit: Microsoft)

After twelve years of going unnoticed, a potential security threat hidden within a Windows defender driver has been exposed and fixed. The weakness in the Microsoft Defender software (as its now known) was actually flagged last November by researchers at security firm SentinelOne, but it's taken Microsoft until this week to finally patch it. 

According to Wired, the role of the driver in question is essentially to remove malicious files, while replacing them with a placeholder file—albeit an unvalidated file—which could potentially have become a target for hackers. According to SentinelOne's senior security researcher, Kasif Dekel, the software bug "allows privilege escalation,” providing administrative privileges to attackers that might attach malware to the temporary driver.

This could easily have resulted in hackers gaining control of your machine, and has put hundreds of thousands of users at risk due to the software coming pre-installed on Windows devices.

But the question remains, how has it gone unnoticed for so long?

Your next machine

(Image credit: Future)

Best gaming PC: the top pre-built machines from the pros
Best gaming laptop: perfect notebooks for mobile gaming

It seems the driver may have slipped under the radar due to it not being stored locally on your machine, instead Windows employs what they call a “dynamic-link library” meaning the driver is only present temporarily, as and when it's needed. 

Thankfully it was only a vulnerability should attackers already have access to your device, whether that be remote or physical, so the threat would have to have come as an aside to other, more prevalent cyber-attack strategies. 

Try not to panic, but this kind of thing happens all the time. It's impossible to catch every bug before software rolls out. Let's just be grateful none of those pesky hackers noticed this one.

Katie Wickens
Hardware Writer

Screw sports, Katie would rather watch Intel, AMD and Nvidia go at it. Having been obsessed with computers and graphics for three long decades, she took Game Art and Design up to Masters level at uni, and has been rambling about games, tech and science—rather sarcastically—for four years since. She can be found admiring technological advancements, scrambling for scintillating Raspberry Pi projects, preaching cybersecurity awareness, sighing over semiconductors, and gawping at the latest GPU upgrades. Right now she's waiting patiently for her chance to upload her consciousness into the cloud.

Latest in Security
An FBI wanted poster for alleged hacker Zhou Shuai.
US Justice Dept announces $10 million bounty on at-large 'hacker-for-hire' cabal it says targeted China critics, religious missionaries, and the Treasury
Kinzie, in an FBI jacket, uses a computer with the logo of the Third Street Saints on it
Have I Been Pwned adds over 284 million compromised passwords from latest breach
A still from a YouTube video of Senator Mark Warner speaking
Telecoms hack on US government officials is 'worst in nations history' and 'the barn door is still wide open' says senator
HDMI cable
Hackers can wirelessly spy on your display by collecting HDMI signal leaks and churning them through an AI, but I wouldn't break out the tin foil just yet
Computer code and text displayed on computer screens. Photographer: Chris Ratcliffe/Bloomberg
Forcing users to periodically change their passwords should go the way of the dodo according to the US government
An original Apple Macintosh Model M0001, as they celebrate 40th anniversary, is on display in between 2024 Apple models at the independent Apple products store chain Amac, on January 24, 2024 in Utrecht, The Netherlands. Based on the Motorola 68000 microprocessor, the Macintosh was the first successful mouse-driven computer with a graphical user interface.
Major browser providers scramble to patch an 18-year-old vulnerability affecting MacOS and Linux systems but Windows remains gloriously immune
Latest in News
Grand Theft Auto 6 trailer still - woman in the front seat of a car, looking out the back window while holding a wad of cash
The specter of a GTA 6 delay haunts the games industry: 'Some companies are going to tank' if they guess wrong, says analyst
Image for
Warhammer 40,000: Darktide’s getting a new roguelite wave defense mode that sounds a whole lot like a souped-up take on Killing Floor
Battle Brothers
Nearly 2 years after its last update, the excellent Battle Brothers gets 'a bucket load of fixes' and free new content
Western outlaws with masks and guns
'Players don't explore': former Grand Theft Auto 6 and Red Dead Online designer lays out the perils of 'open world fatigue'
Person battling bizarre four-eyed monster with stylish UI elements surrounding them
Persona and Metaphor: ReFantazio's UI designer is open to accessibility options for players who find the stylish menus overstimulating: 'That is something we understand we'll need to work on and provide in the future'
Split Fiction screenshot
Split Fiction is reportedly at the center of a bidding war for its movie rights