
In Windows Defender, a built -in Windows antivirus, they found a vulnerability that allowed attackers to gain access to a computer. On May 6, it was found by Google Project Zero .
To access the computer, it was enough for attackers to leave a certain file on the victim’s computer - this could be a letter sent by e -mail, or a download link. Moreover, it was not necessary to launch the file, since the Windows antivirus itself automatically checks all the files that are on the computer. As a result, the computer would be under the control of attackers.
According to Wired, two billion devices on which Windows Defender could be installed potential victims. But Microsoft has already released a special update on May 9: it is installed automatically, so most users are already safe.
Among the safety specialists, antivirus disputes have been underway for years - they are useful or harmful. On the one hand, they are designed to protect computers, on the other hand, they are the same programs as others and are subject to vulnerabilities.
In antiviruses, they had previously found vulnerabilities. In 2016, they were found in Symantec products , and even earlier in McAfee , Fireye and others.
“It is impossible to deny that there are irony that programs designed to protect computers from infection themselves are infected,” says MalWarebytes, a specialist in security, Geor Semhur from the company.