CVE-2024-20671 is a Microsoft Defender Security Feature Bypass Vulnerability affecting Microsoft Windows Defender Antimalware Platform. Rated Medium severity (CVSS 5.5), this local attack requires low privileges and complexity, potentially leading to high impact on availability, though confidentiality and integrity are not directly affected. There is currently no evidence of active exploitation, public exploit code, or inclusion in CISA's KEV catalog, despite some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.18.24010.12CPE matchmatch criteria | cpe:2.3:a:microsoft:windows_defender_antimalware_platform:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.