PT-2023-2750 · Microsoft · Defender+1

Omer Attias

+1

·

Published

2023-04-14

·

Updated

2024-05-29

·

CVE-2023-24934

CVSS v3.1

6.2

Medium

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Microsoft Malware Protection Engine (MPE) (affected versions not specified) Microsoft Defender (affected versions not specified)
Description The issue is related to a lack of protection for service data in the Microsoft Malware Protection Engine (MPE). Exploitation of this issue may allow an attacker to disclose protected information. There is no information provided about the estimated number of potentially affected devices worldwide or real-world incidents where this issue was exploited.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authentication

Information Disclosure

Weakness Enumeration

Related Identifiers

BDU:2023-02598
CVE-2023-24934

Affected Products

Defender
Malware Protection Engine