EXPOSURES › CVE-2021-1647
CVE-2021-1647
HIGH ⌖ ON CISA KEV · EXPLOITEDMicrosoft Defender contained an unpatched remote code execution vulnerability that was actively exploited in the wild.
Microsoft Defender had an unpatched remote code execution vulnerability that was actively exploited in the wild, allowing attackers to execute arbitrary code on systems. This failure matters to DIB organizations because it demonstrates the risk of relying on security software that is not promptly patched, potentially leading to system compromise and data breaches. Organizations should ensure all security software is regularly updated and monitored for known vulnerabilities.
Shame score — The vulnerability was unpatched and actively exploited in the wild, indicating a failure to address known security flaws promptly.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Defender contains an unspecified vulnerability that allows for remote code execution.
"Microsoft Defender contains an unspecified vulnerability that allows for remote code execution."
| PRODUCT | STATUS |
|---|---|
| Azure Commercial Cloud Microsoft |
Authorized |
| Azure Government (includes Dynamics 365) Microsoft |
Authorized |
| Microsoft Office 365 GCC High Microsoft |
In Process |
| Office 365 Multi-Tenant & Supporting Services Microsoft |
Authorized |