Netskope Threat Labs

FILE-EXECUTABLE Microsoft Windows Defender buffer overflow attempt

IPS-SWG

2 SIDs: 56857, 56858

First seen
June 2024
Last seen
October 2026

Detects content exploiting CVE-2021-1647, a buffer overflow in the Microsoft Defender malware engine that can allow code execution. A crafted scanned file corrupts the engine itself, which can disable or hijack the antivirus on the host.