From 1c711364e56f6cb4e7d00d897819deabc7a55a74 Mon Sep 17 00:00:00 2001 From: nu11secur1ty Date: Wed, 14 Sep 2022 10:06:28 +0300 Subject: [PATCH] Add files via upload --- .../Docs/report.txt | 40 +++++++++++++++++++ 1 file changed, 40 insertions(+) create mode 100644 Windows-Defender-bypass-authentication/Docs/report.txt diff --git a/Windows-Defender-bypass-authentication/Docs/report.txt b/Windows-Defender-bypass-authentication/Docs/report.txt new file mode 100644 index 0000000..d909a2f --- /dev/null +++ b/Windows-Defender-bypass-authentication/Docs/report.txt @@ -0,0 +1,40 @@ +## Title: Windows Defender-4.18.2104.10, Engine Version-1.1.17300.4, Antivirus Version-1.321.69.0 User-Bypass-Athentication +## Author: nu11secur1ty +## Date: 09.14.2022 +## Vendor: https://www.microsoft.com/ +## Software: https://www.microsoft.com/en-us/windows/comprehensive-security +## Reference: https://github.com/nu11secur1ty/Windows11Exploits/tree/main/Windows-Defender-bypass-authentication + + +## Description: +The Windows Defender-4.18.2104.10, (Engine Version-1.1.17300.4, and Antivirus Version-1.321.69.0), is suffering from User Bypass Authentication. +The malicious user can transport a malicious compressed `jpg` file by using a USB-flash drive or whatever device to infect the poor victim - all normal users. +The victim can infect a lot of computers if he spread this `jpg` file hows in internal or external networks, it's depending on the case. +This can be done with a user account without any restriction from Windows Defender! + +## WARNING: +This is not a joke! +Keep your Windows Defender up to the date! +This could be saving you before will be late for defense! + +##STATUS: +HIGH Vulnerability + +[+]Exploit: +[href](https://github.com/nu11secur1ty/Windows11Exploits/tree/main/Windows-Defender-bypass-authentication/Exploit) + +## Reproduce: +[href](https://github.com/nu11secur1ty/Windows11Exploits/tree/main/Windows-Defender-bypass-authentication) + +## Proof and Exploit: +[href](https://streamable.com/qbufr3) + + +-- +System Administrator - Infrastructure Engineer +Penetration Testing Engineer +Exploit developer at https://packetstormsecurity.com/ +https://cve.mitre.org/index.html and https://www.exploit-db.com/ +home page: https://www.nu11secur1ty.com/ +hiPEnIMR0v7QCo/+SEH9gBclAAYWGnPoBIQ75sCj60E= + nu11secur1ty