CVE-2024-2067112.03.2024, 17:15Microsoft Defender Security Feature Bypass VulnerabilityEnginsightProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVectorNISTNIST5.5 MEDIUMLOCALLOWLOWCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HmicrosoftCNA5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:CCISA-ADPADP------CVEADP------Base ScoreCVSS 3.xEPSS ScorePercentile: 58%VendorProductVersionmicrosoftwindows_defender_antimalware_platform𝑥< 4.18.24010.12𝑥= Vulnerable software versionsCommon Weakness EnumerationCWE-276 - Incorrect Default PermissionsDuring installation, installed file permissions are set to allow anyone to modify those files.Referenceshttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-20671https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-20671