{"id":7615,"date":"2025-10-12T10:03:27","date_gmt":"2025-10-12T10:03:27","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/10\/12\/microsoft-defender-vulnerabilities-allow-attackers-to-bypass-authentication-and-upload-malicious-files\/"},"modified":"2025-10-12T10:03:27","modified_gmt":"2025-10-12T10:03:27","slug":"microsoft-defender-vulnerabilities-allow-attackers-to-bypass-authentication-and-upload-malicious-files","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/10\/12\/microsoft-defender-vulnerabilities-allow-attackers-to-bypass-authentication-and-upload-malicious-files\/","title":{"rendered":"Microsoft Defender Vulnerabilities Allow Attackers to Bypass Authentication and Upload Malicious Files"},"content":{"rendered":"<p>    Microsoft Defender Vulnerabilities Allow Attackers to Bypass Authentication and Upload Malicious Files<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>Critical flaws uncovered in the network communication between Microsoft Defender for Endpoint (DFE) and its cloud services, allowing post-breach attackers to bypass authentication, spoof data, disclose sensitive information, and even upload malicious files to investigation packages.<\/p>\n<p>These vulnerabilities, detailed in a recent analysis by InfoGuard Labs, highlight ongoing risks in <a href=\"https:\/\/cybersecuritynews.com\/best-edr-tools\/\" target=\"_blank\" rel=\"noreferrer noopener\">endpoint detection and response (EDR) <\/a>systems, potentially undermining incident response efforts.<\/p>\n<p>Reported to Microsoft\u2019s Security Response Center (MSRC) in July 2025, the issues were deemed low severity, with no fixes confirmed as of October 2025.<\/p>\n<p>The research builds on prior explorations of EDR attack surfaces, focusing on the agent\u2019s interaction with cloud backends. By intercepting traffic using tools like Burp Suite and bypassing certificate pinning through memory patches in WinDbg, the analysis revealed how DFE\u2019s MsSense.exe process handles commands and data uploads.<\/p>\n<p><a href=\"https:\/\/cybersecuritynews.com\/domain-fronting-attack\/\">Certificate pinning<\/a>, a common security measure, was circumvented by altering the CRYPT32!CertVerifyCertificateChainPolicy function to always return a valid result, enabling plaintext inspection of HTTPS traffic.<\/p>\n<p>Similar patches were applied to SenseIR.exe for complete interception, including Azure Blob uploads.<\/p>\n<figure class=\"wp-block-image size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiGaDsldYHtTienuYSzrnIwwYjx9Fh60-e3XCUmL0fSBKXu1pthukA6ze2dZx1KWDZh-8bt7ba-1mrh2gNMXR-8dGTVY2vcUZ8muWex7Ru1m5FIwYgQ_bsjBKKbHAVHi3-jCDwMHcYjLmK_wvqY21b7c2o8yK48ZTe9Ns-RrWjZFNEmOsaNXCbfMSS0-smP\/s16000\/Azure%2520Blob%2520uploads.webp?ssl=1\" alt=\"Azure Upload\"><figcaption class=\"wp-element-caption\">Azure Upload<\/figcaption><\/figure>\n<h2 class=\"wp-block-heading\" id=\"h-authentication-bypasses-and-command-interception\"><strong>Authentication Bypasses and Command Interception<\/strong><\/h2>\n<p>According to InfoGuard Labs the <a href=\"https:\/\/labs.infoguard.ch\/posts\/attacking_edr_part5_vulnerabilities_in_defender_for_endpoint_communication\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">core issue<\/a> lies in the agent\u2019s requests to endpoints like https:\/\/[location-specific-host]\/edr\/commands\/cnc, where it polls for commands such as isolation, forensics collection, or scans.<\/p>\n<p>Despite including Authorization tokens and Msadeviceticket headers, the backend ignores them entirely. An attacker with the machine ID and tenant ID easily obtainable by low-privileged users via registry reads can impersonate the agent and intercept responses.<\/p>\n<p>For instance, an intruder tool like Burp\u2019s Intruder can continuously query the endpoint, snatching available commands before the legitimate agent receives them.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiTVxMEMYd6EQPchDs5h7xcQQ-S36METkNiu2HirCmANV_H8ROTiPIMT9U9OT-gOWJzBNo71PNeTz-ReS0bmBLIhBAa7HNmPq8RrAwewfzxbiGEFwOCXkZKhhzCqTrHY1ff_jrZ9Sz7wQ-eyrq8TCrEyqVYFt2UQEDitlFtam8nUhTTBKWIr9T1fmmORkKJ\/s16000\/Commands.webp?ssl=1\" alt=\"\"><\/figure>\n<\/div>\n<p>This allows spoofing responses, such as faking an \u201cAlready isolated\u201d status for an isolationcommand, leaving the device unisolated while the Microsoft Defender Portal reports it as secured.<\/p>\n<p>The serialization format, often in Microsoft Bond, complicates manual crafting, but capturing and modifying legitimate responses suffices for proof-of-concept exploits.<\/p>\n<p>A parallel vulnerability affects \/senseir\/v1\/actions\/ endpoints for Live Response and Automated Investigations. Here, CloudLR tokens are similarly ignored, obtainable without authentication using just the machine ID.<\/p>\n<p>Attackers can decode action payloads with custom scripts leveraging large language models for Bond deserialization and upload fabricated data to provided <a href=\"https:\/\/cybersecuritynews.com\/microsoft-azure-storage-forensics\/\" target=\"_blank\" rel=\"noreferrer noopener\">Azure Blob<\/a> URIs via SAS tokens, which remain valid for months.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-information-disclosure-and-malicious-file-risks\"><strong>Information Disclosure and Malicious File Risks<\/strong><\/h2>\n<p>Unauthenticated access extends to incident response (IR) exclusions via the registration endpoint, requiring only the organization ID from the registry.<\/p>\n<p>More alarmingly, polling \/edr\/commands\/cnc without credentials yields an 8MB configuration dump, including RegistryMonitoringConfiguration, DriverReadWriteAccessProcessList, and ASR rules. While not tenant-specific, this data reveals detection logic valuable for evasion.<\/p>\n<figure class=\"wp-block-image size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjM4XYss3nPayDe7wJmOw33DIbAfUpm3ElISb7TFfYP7EFm8ULYVcpntn0wzpVJS4oqRRVOTIGZ1Qin-M4FiS0sxbR6msfowCEwAOA5K2b3mIJcpbGkejrWDGc16s3smBsW4EiLudrntuXbs8BViCVID5hHNCCGwxaX1PNsnaeal2ethw6eehxkCtDtX6SV\/s16000\/information.webp?ssl=1\" alt=\"\"><\/figure>\n<p>Post-breach, attackers can enumerate investigation packages on the filesystem, readable by any user, containing autoruns, installed programs, and network connections.<\/p>\n<p>For ongoing investigations, spoofed uploads to these packages enable embedding malicious files with innocuous names, tricking analysts into execution during review.<\/p>\n<p>These flaws underscore the challenges in securing EDR communications, where simple oversights persist despite multiple token types. The analyst urges remediation, arguing that post-breach disruption and analyst-targeted attacks merit a higher priority than MSRC\u2019s assessment.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong>Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>, <a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and <a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a> for daily cybersecurity updates. <a href=\"https:\/\/cybersecuritynews.com\/contact-us\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Contact us<\/a> to feature your stories.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/microsoft-defender-authentication-bypass\/\">Microsoft Defender Vulnerabilities Allow Attackers to Bypass Authentication and Upload Malicious Files<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Guru Baran<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/microsoft-defender-authentication-bypass\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Microsoft Defender Vulnerabilities Allow Attackers to Bypass Authentication and Upload Malicious Files Critical flaws uncovered in the network communication between Microsoft Defender for Endpoint (DFE) and its cloud services, allowing post-breach attackers to bypass authentication, spoof data, disclose sensitive information, and even upload malicious files to investigation packages. These vulnerabilities, detailed in a recent analysis [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,131,395],"tags":[130],"class_list":["post-7615","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-vulnerability","category-windows","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/7615"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=7615"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/7615\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=7615"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=7615"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=7615"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}