Microsoft Defender Vulnerability: Bypass Authentication & Upload Malicious Files

A critical vulnerability in Microsoft Defender for Endpoint (DFE) has been revealed, enabling attackers to bypass authentication and upload malicious files. The flaw lies within the network communication between DFE and its cloud services. This vulnerability allows attackers, after gaining access to a system, to circumvent authentication measures, forge data, leak sensitive information, and even deploy malicious files into investigation packages. This issue was brought to light by 23pds, Chief Information Security Officer at SlowMist Technology.