CVE-2021-42298: Microsoft Defender Remote Code Execution Vulnerability
Microsoft Defender Remote Code Execution Vulnerability
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.1.18700.3
Event History
Frequently Asked Questions
What is CVE-2021-42298?
CVE-2021-42298 is a vulnerability in Microsoft Defender that allows remote code execution.
How severe is CVE-2021-42298?
CVE-2021-42298 has a severity rating of 7.8, which is considered critical.
What software is affected by CVE-2021-42298?
The affected software is Microsoft Malware Protection Engine version up to exclusive 1.1.18700.3.
How can I fix CVE-2021-42298?
To fix CVE-2021-42298, update your Microsoft Malware Protection Engine to a version higher than 1.1.18700.3.
Where can I find more information about CVE-2021-42298?
You can find more information about CVE-2021-42298 in the Microsoft Security Guidance Advisory at the following link: [https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-42298](https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-42298).