msdt-follina icon indicating copy to clipboard operation
msdt-follina copied to clipboard

Can we Bypass Windows Defender ?

Open DungLeMTA opened this issue 2 years ago • 5 comments

Can we use the malicious word document and bypass Windows Defender ?

DungLeMTA avatar Jun 03 '22 07:06 DungLeMTA

My educated guess is: until Microsoft themselves resolve the Zero-Day it will remain undetected by Windows Defender, I'm probably wrong though.

You can also read this: https://www.trellix.com/en-sg/about/newsroom/stories/threat-labs/follina-microsoft-office-zero-day-cve-2022-30190.html#:~:text=The%20'Follina'%20zero%2Dday,can%20bypass%20Windows%20Defender%20detection.

El-Vim55 avatar Jun 07 '22 12:06 El-Vim55

My educated guess is: until Microsoft themselves resolve the Zero-Day it will remain undetected by Windows Defender, I'm probably wrong though.

You can also read this: https://www.trellix.com/en-sg/about/newsroom/stories/threat-labs/follina-microsoft-office-zero-day-cve-2022-30190.html#:~:text=The%20'Follina'%20zero%2Dday,can%20bypass%20Windows%20Defender%20detection.

John Hammond already has submitted the fault to the Microsoft team and if the system is up to date windows will surely detect the vulnerability

lakshya2207 avatar Jun 11 '22 09:06 lakshya2207

@lakshya2207 Ah ok, thanks for letting us know!

El-Vim55 avatar Jun 11 '22 11:06 El-Vim55

Hi

I tried the exploit and i have a question now :
The exploit is done when the Windows Defender is off. dose it mean the vulnerability still exists in msdt service. and Windows prevents it just using defender? if so, what would it be if we obfuscatethe html payload ? dose it bypass the antivirus. how defender is preventing this exploit ? it's signature base or it prevents calling msdt through web ? this is the message i got from the windows antivirus :

image

Is there a way to change html_payload in the code ?

ElizabethHanson1999 avatar Oct 18 '22 09:10 ElizabethHanson1999

@ElizabethHanson1999 I tried it, I tried obfuscating html payload but Windows Defender caught any powershell commands, so it is not effective

DungLeMTA avatar Oct 18 '22 13:10 DungLeMTA