• Skip to main content
  • Skip to header right navigation
  • Skip to site footer
iGuRu

iGuRu

Real-time Technology News. Opinions & Tweaks

  • / news
  • / infosec
  • / tools
  • / tweaks
  • / dummies
  • / opinions
  • / support
  • / yourpost
home / News / Windows Defender has removed the ability to download files

Windows Defender has removed the ability to download files

18/09/2020 18:47 by giorgos

Microsoft has removed the ability to download files through Windows Defender after it turned out how it could be used by intruders to download malware to a computer.

Last week, we reported that Microsoft quietly added the ability to download files through Windows Defender for some unknown reason.Microsoft Defender - Windows Defender has removed the ability to download files

When this was discovered, the cyber security community expressed concern that Microsoft would allow Defender to be used by attackers as LOLBIN.

LOLBINs, or living-off-the-land binaries, are legitimate operating system files that can be compromised for malicious purposes.

To download a file, users had to run a Microsoft Antimalware command line utility (MpCmdRun.exe) with the -DownloadFile command, as shown below.

MpCmdRun.exe -DownloadFile -url [url] -path [path_to_save_file]

In tests conducted by security researchers, I was able to download any files (even ransomware_, to their systems.

Windows Defender can quickly detect malware, but other security software will not detect the download made by Microsoft security application.

With yesterday's release of the Windows Defender Antimalware Client in version 4.18.2009.2-0, it seems that Microsoft has changed the capabilities of MpCmdRun.exe.

Microsoft has virtually removed the ability to download files through the command line utility MpCmdRun.exe.

So if you try to download a file using MpCmdRun.exe you will encounter an error stating "CmdTool: Invalid command line argument."
Also the -DownloadFile command line setting has been removed from the help screen.

Windows Defender has removed the ability to download files was last modified: 18 September, 2020, 6: 47 mm by giorgos

spread the news

  • Facebook
  • Twitter
  • Reddit
  • Printing
  • Email

Read them Technology News from all over the world, with the validity of iGuRu.gr

Follow us on Google News


Competition: Newstag: microsoft defender

You May Also Like

Do you have the secure version of Microsoft Defender?
Microsoft Defender is now detecting Zerologon attacks
Microsoft Defender ATP with reports of vulnerable devices

About Us giorgos

George still wonders what he's doing here ...

Previous Post: « Microsoft SecretManagement Preview 3
Next Post: Windows 10 October 2020 or 20H2 Release Preview »

Reader Interactions

Comment Policy:

IGuRu.gr does not publish the comments immediately. Malicious comments, comments that include ads, or comments that are offensive are deleted without notice. We do not adopt the opinions expressed by our readers.
Your comments will be displayed after approval by the administrators


Leave your comment
Ακύρωση απάντησης

Your email address is not published. Τα υποχρεωτικά πεδία σημειώνονται με *

 

 © 2021 · iGuRu.gr · ☢ · Keep It Simple Stupid Genesis theme

about  ·   get in touch  ·  rss  ·  sitemap  ·  cough

loading Cancel
Could not post post - check your email address!
Email verification failed, please try again
Your blog can not post posts via email.