CVE-2023-21809 is a Microsoft Defender for Endpoint Security Feature Bypass Vulnerability affecting Microsoft Defender Security Intelligence Updates. With a CVSS score of 7.8 (HIGH), this vulnerability allows an attacker to bypass security features with low attack complexity, potentially leading to high impact on confidentiality, integrity, and availability. While there is no public exploit code available (Metasploit, Nuclei, ExploitDB), it was mentioned in one article regarding Microsoft's February 2023 Patch Tuesday, indicating some media coverage and community discussion. The vulnerability is not listed in CISA's KEV catalog and its EPSS score is relatively low, suggesting a lower probability of exploitation in the wild compared to many other CVEs.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.379.200.0CPE matchmatch criteria | cpe:2.3:a:microsoft:defender_security_intelligence_updates:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.