CVE-2023-21809
📛 CVE Title
Microsoft Defender for Endpoint Security Feature Bypass Vulnerability
Description
Microsoft Defender for Endpoint Security Feature Bypass Vulnerability
Overview
- State
- PUBLISHED
- Assigner (CNA)
- microsoft
- CVSS severity
- HIGH
- CVSS score
- 7.8 / 10
- CVSS vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C- Effective score
- 7.8 / 10 HIGH source: CNA overview
- MSRC score
- 7.8 / 10 HIGH MS rating: Important · Security Feature Bypass
- CWE(s)
- —
- Reserved
- 2022-12-16
- Published
- 2023-02-14 08:00 UTC
- Last updated
- 2023-02-21 08:00 UTC
- Source
- https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2023/21xxx/CVE-2023-21809.json
- Linked Threat
- CVE-2023-21809 — Microsoft Defender for Endpoint Security Feature Bypass Vulnerability
European Union Vulnerability Database ENISA EUVD
ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.
- EUVD ID
-
EUVD-2023-25975 - Assigner
- microsoft
- Published
- Feb 14, 2023, 7:33:13 PM
- Updated
- Jan 1, 2025, 12:40:48 AM
- EUVD base score (CVSS 3.1)
-
7.8 / 10
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C - EUVD-reported EPSS
- 1.2600
- Vendors
- Microsoft
- Products
-
Microsoft Defender Security Intelligence Updates (1.0.0 <1.379.200.0)
- Aliases
-
GHSA-fvfp-w3v3-v2cp
ENISA description: Microsoft Defender for Endpoint Security Feature Bypass Vulnerability
EUVD references (1)
Microsoft Security Response Center MSRC
Microsoft's vendor-authoritative record from the Security Update Guide — its own CVSS score, impact, severity rating, exploit assessment, and KB-article fixes. Refreshed 2026-08-11 01:49 UTC (source: CVRF).
- MS severity
- Important
- Impact
- Security Feature Bypass
- MS CVSS base score
- 7.8 / 10 (temporal 6.8)
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C - Exploit assessment
- Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;DOS:N/A
- Release
- 2023-Feb
Microsoft remediations / KB articles (1)
- Release Notes — Vendor Fix / Security Update (fixed build 1.379.200.0)
Microsoft FAQ (3)
According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?
A user needs to be tricked into running malicious files.
What kind of security feature could be bypassed by successfully exploiting this vulnerability?
An attacker who successfully exploited this vulnerability could bypass the Windows Defender Attack Surface Reduction blocking feature.
How can I check if I'm protected from this vulnerability?
This vulnerability existed in the Defender Security Intelligence Updates and not the Malware protection engine. The version of the signatures that addressed the vulnerability is 1.379.200.0 and was updated automatically. Check the current version in Windows Update history Definition Updates to see the most recently installed definitions.
Affected products (1)
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Microsoft | Microsoft Defender Security Intelligence Updates |
1.0.0 (affected)
|
Unknown |
Vendor references (1)
References embedded in the original CVE record by the assigning CNA.
Web references (1)
DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.
Remediations (18)
Remediations are stored against the linked Threat row; the list below is deduplicated across both pages.
-
web:support.google.com
Your innovation is what drives our shared success, but with it comes responsibility. These Developer Program Policies, along with the Developer Distribution Agreement, ensure that together we continue to deliver the world's most innovative and trusted apps to over a billion people through Google Play. We invite you to explore our policies below.
2026-06-04 13:45 UTC -
web:www.grammarly.com
Grammarly makes AI writing convenient. Work smarter with personalized AI guidance and text generation on any app or website.
2026-06-04 13:45 UTC -
web:wa.me
Hosted by WhatsApp 2026 © WhatsApp LLC Privacy & Terms
2026-06-04 13:45 UTC -
web:msrc.microsoft.com
Security Update Guide - Microsoft Security Response Center
2026-06-04 13:45 UTC -
web:www.virustotal.com
VirusTotal is a platform for scanning files and URLs for viruses, malware, and other threats using multiple antivirus engines.
2026-06-04 13:45 UTC -
web:www.youtube.com
New video tomorrow y'all…I have to fix all the mic audio on it 165 21 Montoya Twinz
2026-06-04 13:45 UTC -
web:www.youtube.com
Today marks a very special day for ARK as the game officially celebrates 11 years since its original launch, and Studio Wildcard has released a brand new upd...
2026-06-04 13:45 UTC -
web:learn.microsoft.com
Troubleshoot SPF, DKIM, and DMARC email authentication failures in Exchange Online and Microsoft 365 with quick-reference tables and detailed guidance.
2026-06-04 13:45 UTC -
web:www.securityweek.com
Microsoft has announced mitigations for CVE -2026-45585, a BitLocker bypass triggered via FsTx in Windows Recovery.
2026-05-22 05:47 UTC -
web:cybersecuritynews.com
No patch has been released yet; Microsoft has instead issued a multi-step manual mitigation guide while a formal security update is prepared. Windows BitLocker Security Bypass The vulnerability originates in WinRE's handling of the BootExecute registry value under HKLM\ControlSet001\Control\Session Manager.
2026-05-22 05:47 UTC -
web:zecurit.com
Get the complete breakdown of Microsoft's May 2026 Patch Tuesday. We analyze the latest security updates and all critical CVEs .
2026-05-22 05:47 UTC -
web:knowledge.broadcom.com
8. Reporting Compliance for Patch Management: Found on the Console > Reports > All Reports > Software > Patch Management > Compliance Run the Windows Compliance by Bulletin, Computer or Update to view vulnerabilities in the environment. These reports can be found in Home> Patch Management> Compliance and Remediation Caution!
2026-05-22 05:47 UTC -
web:krebsonsecurity.com
Microsoft expects that exploitation is more likely. May's Patch Tuesday is a welcome respite from April, which saw Microsoft fix a near-record 167 security flaws.
2026-05-22 05:47 UTC -
web:portal.msrc.microsoft.com
The Security Update Guide provides information on the latest Microsoft security updates, helping users understand and address potential vulnerabilities effectively.
2026-05-22 05:47 UTC -
web:windowsreport.com
It's that time of the month again: Microsoft has rolled out its Patch Tuesday updates for Windows 11 versions 23H2, 22H2, and 21H2. Windows 11 23H2 and 22H2 users will see their systems updated through KB5041585, while those on 21H2 will receive KB5041592.
2026-05-22 05:47 UTC -
web:www.bleepingcomputer.com
Today is Microsoft's March 2026 Patch Tuesday with security updates for 79 flaws, including 2 publicly disclosed zero-day vulnerabilities.
2026-05-22 05:47 UTC -
web:www.cve.org
At cve .org, we provide the authoritative reference method for publicly known information-security vulnerabilities and exposures
2026-05-22 05:47 UTC -
web:www.helpnetsecurity.com
Microsoft is working on a fix for CVE -2026-45585 (aka "Yellowkey"), a vulnerability that can be used to bypass Windows' BitLocker protection.
2026-05-22 05:47 UTC
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.
Raw JSON
The full cvelistV5 record. Download as CVE-2023-21809.json.
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2024-08-02T09:51:50.948Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"name": "Microsoft Defender for Endpoint Security Feature Bypass Vulnerability",
"tags": [
"vendor-advisory",
"x_transferred"
],
"url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-21809"
}
],
"title": "CVE Program Container"
}
],
"cna": {
"affected": [
{
"platforms": [
"Unknown"
],
"product": "Microsoft Defender Security Intelligence Updates",
"vendor": "Microsoft",
"versions": [
{
"lessThan": "1.379.200.0",
"status": "affected",
"version": "1.0.0",
"versionType": "custom"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:microsoft:defender_for_endpoint_Security_Intelligence_Updates:*:*:*:*:*:-:*:*",
"versionEndExcluding": "1.379.200.0",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"datePublic": "2023-02-14T08:00:00.000Z",
"descriptions": [
{
"lang": "en-US",
"value": "Microsoft Defender for Endpoint Security Feature Bypass Vulnerability"
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en-US",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"description": "Security Feature Bypass",
"lang": "en-US",
"type": "Impact"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2025-01-01T00:40:48.788Z",
"orgId": "f38d906d-7342-40ea-92c1-6c4a2c6478c8",
"shortName": "microsoft"
},
"references": [
{
"name": "Microsoft Defender for Endpoint Security Feature Bypass Vulnerability",
"tags": [
"vendor-advisory"
],
"url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-21809"
}
],
"title": "Microsoft Defender for Endpoint Security Feature Bypass Vulnerability"
}
},
"cveMetadata": {
"assignerOrgId": "f38d906d-7342-40ea-92c1-6c4a2c6478c8",
"assignerShortName": "microsoft",
"cveId": "CVE-2023-21809",
"datePublished": "2023-02-14T19:33:13.148Z",
"dateReserved": "2022-12-16T22:13:41.242Z",
"dateUpdated": "2025-01-01T00:40:48.788Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}