Microsoft quietly repairs Windows Defender security hole CVE-2017-11937

Credit to Author: Woody Leonhard| Date: Fri, 08 Dec 2017 07:23:00 -0800
Many malware researchers were surprised to find an unexpected patch on their machines yesterday. It didn’t arrive through the front door — Windows Update wasn’t involved. Instead, the new version of mpengine.dll arrived automatically, around the back, even if you have Windows Update turned off.
This vulnerability is particularly nasty. If the Malware Protection Engine scans a jimmied file, the file can take over your computer and run whatever it wants. Since the MPE routinely runs all the time, in the background, that means a bad file could infect your computer in myriad ways. To quote Microsoft’s Security Vulnerability notice:

It snowed in Austin, Texas last night. It’s not a big deal for those of you who live in areas where you’re used to snow, but for those of us who are native Texans, it’s a big deal. Funny enough, I had scheduled a maintenance appointment for later today to make sure our heater is…


Security Bugs – “The Root of all Evil” by Paul Ionescu, Security Architect Looking back at some of the famous security breaches of 2017 we find that they have been caused by software bugs. The WannaCry attack which impacted computers in 150 countries for an estimated cost of $4 billion used a memory flaw in…
Tips to utilizing app permissions in the world’s most popular mobile operating system. – by Ian Grutze, Senior Global Product Manager Mobile devices are amazing tools that can enrich your life in many ways. Need to solve a problem…? There’s probably an app for that. As these devices mature, and as we weave them into our daily…