Microsoft Defender for Endpoint Spoofing Vulnerability
🔗 CVE IDs covered (1)
📋 Description
According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability? Successful exploitation of this vulnerability requires an attacker to gather information specific to the environment of the targeted component.
How can I verify that the update is installed? Customers wanting to ensure the client has been updated can run the MDE Client Analyzer on the device. When running the analyzer on a Windows device that does not have the security update, the analyzer will present a warning (ID 121035) indicating missing patch and directing to relevant online article. Additionally, if the update is installed, but the Anti-Spoofing capability is not in a stable state, the analyzer will present warning (ID 121036) indicating an issue and providing additional online guidance or callout to reach out to Microsoft support if issue persists.
Where can I get more information? For more information, please see the blog post here.
🎯 Affected products30
- Microsoft Defender for Endpoint EDR sensor on Windows Server 2012 R2
- Microsoft Defender for Endpoint EDR sensor on Windows Server 2012 R2 (Server Core installation)
- Microsoft Defender for Endpoint EDR sensor on Windows Server 2016
- Microsoft Defender for Endpoint EDR sensor on Windows Server 2016 (Server Core installation)
- Microsoft Defender for Endpoint for Android
- Microsoft Defender for Endpoint for Linux
- Microsoft Defender for Endpoint for Mac
- Microsoft Defender for Endpoint for Windows on Windows 10 Version 1809 for 32-bit Systems
- Microsoft Defender for Endpoint for Windows on Windows 10 Version 1809 for ARM64-based Systems
- Microsoft Defender for Endpoint for Windows on Windows 10 Version 1809 for x64-based Systems
- Microsoft Defender for Endpoint for Windows on Windows 10 Version 1909 for 32-bit Systems
- Microsoft Defender for Endpoint for Windows on Windows 10 Version 1909 for ARM64-based Systems
- Microsoft Defender for Endpoint for Windows on Windows 10 Version 1909 for x64-based Systems
- Microsoft Defender for Endpoint for Windows on Windows 10 Version 20H2 for 32-bit Systems
- Microsoft Defender for Endpoint for Windows on Windows 10 Version 20H2 for ARM64-based Systems
- Microsoft Defender for Endpoint for Windows on Windows 10 Version 21H1 for 32-bit Systems
- Microsoft Defender for Endpoint for Windows on Windows 10 Version 21H1 for ARM64-based Systems
- Microsoft Defender for Endpoint for Windows on Windows 10 Version 21H1 for x64-based Systems
- Microsoft Defender for Endpoint for Windows on Windows 10 Version 21H2 for 32-bit Systems
- Microsoft Defender for Endpoint for Windows on Windows 10 Version 21H2 for ARM64-based Systems
- Microsoft Defender for Endpoint for Windows on Windows 10 Version 21H2 for x64-based Systems
- Microsoft Defender for Endpoint for Windows on Windows 11 version 21H2 for ARM64-based Systems
- Microsoft Defender for Endpoint for Windows on Windows 11 version 21H2 for x64-based Systems
- Microsoft Defender for Endpoint for Windows on Windows Server 2019
- Microsoft Defender for Endpoint for Windows on Windows Server 2019 (Server Core installation)
- Microsoft Defender for Endpoint for Windows on Windows Server 2022
- Microsoft Defender for Endpoint for Windows on Windows Server 2022 (Server Core installation)
- Microsoft Defender for Endpoint for Windows on Windows Server 2022 Datacenter: Azure Edition
- Microsoft Defender for Endpoint for Windows on Windows Server, version 20H2 (Server Core Installation)
- Microsoft Defender for Endpoint for iOS
✅ Remediation
KBRelease Notes (Security Update) — fixed build 101.60.93 KBRelease Notes (Security Update) — fixed build 101.60.91 KBRelease Notes (Security Update) — fixed build 1.0.3011.0302 KBRelease Notes (Security Update) — fixed build 1.1.18090109 KB5011487 (Security Update) — fixed build 10.0.19042.1586 KB5011485 (Security Update) — fixed build 10.0.18363.2158 KB5011493 (Security Update) — fixed build 10.0.22000.556 KB5011487 (Security Update) — fixed build 10.0.19044.1586 KB5011497 (Security Update) — fixed build 10.0.20348.587 KB5011580 (Security Hotpatch Update) — fixed build 10.0.20348.580 KB5011487 (Security Update) — fixed build 10.0.19043.1586 KB5011503 (Security Update) — fixed build 10.0.17763.2686 KBInformation (Security Update) — fixed build 10.8047.22439
🔗 References (17)
- advisoryhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-23278
- patchhttps://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/linux-updates?view=o365-worldwide
- patchhttps://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/mac-updates?view=o365-worldwide
- referencehttps://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/mtd?view=o365-worldwide
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5011487
- referencehttps://support.microsoft.com/help/5011487
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5011485
- referencehttps://support.microsoft.com/help/5011485
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5011493
- referencehttps://support.microsoft.com/help/5011493
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5011497
- referencehttps://support.microsoft.com/help/5011497
- referencehttps://support.microsoft.com/help/5011580
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5011503
- referencehttps://support.microsoft.com/help/5011503
- patchhttps://www.catalog.update.microsoft.com/Search.aspx?q=KB5005292
- referencehttps://support.microsoft.com/en-us/topic/microsoft-defender-for-endpoint-update-for-edr-sensor-f8f69773-f17f-420f-91f4-a8e5167284ac