Ormandy, who is part of Google’s Project Zero security program, discovered the vulnerability on June 9 and reported it to Microsoft privately to give the software giant the chance to release a patch. As per the policy of Project Zero, vulnerabilities are made public 90 days after the vendor is contacted, if a patch is not released in the meantime.
Microsoft, however, has already published a patch for this Windows Defender flaw, so Ormandy published details on Friday, once again showing that without sandboxing, the antivirus engine is prone to more similar security issues.
Update your systems to stay secure
For the more tech-savvy users, Ormandy explains the bug impacts the x86 emulator built for Windows Defender, which Microsoft has left un-sandboxed on purpose.
“I discussed Microsof...
SOCIAL SHARE CARD GENERATOR