Microsoft has removed the ability to download files through Windows Defender after it turned out how it could be used by intruders to download malware to a computer.
Last week, we reported that Microsoft quietly added the ability to download files through Windows Defender for some unknown reason.
When this was discovered, the cyber security community expressed concern that Microsoft would allow Defender to be used by attackers as LOLBIN.
LOLBINs, or living-off-the-land binaries, are legitimate operating system files that can be compromised for malicious purposes.
Για να κατεβάσουν ένα αρχείο, οι χρήστες έπρεπε να τρέξουν ένα βοηθητικό πρόγραμμα γραμμής orders of services Microsoft Antimalware (MpCmdRun.exe) with the -DownloadFile command, as shown below.
MpCmdRun.exe -DownloadFile -url [url] -path [path_to_save_file]
In tests conducted by security researchers, I was able to download any files (even ransomware_, to their systems.
Windows Defender can quickly detect malware, but other security software will not detect the download made by Microsoft security application.
With yesterday's release of the Windows Defender Antimalware Client in version 4.18.2009.2-0, it seems that Microsoft has changed the capabilities of MpCmdRun.exe.
Microsoft has effectively removed the ability to download files through the prolettercommand prompt MpCmdRun.exe.
So if you try to download a file using MpCmdRun.exe it will show one error which will state “CmdTool: Invalid command line argument.”
Also the -DownloadFile command line setting has been removed from the help screen.