Vulnerability record · CVE-2021-1647 · published 12 January 2021
CVE-2021-1647: Microsoft Defender Remote Code Execution Vulnerability
Microsoft · Windows Defender
CVE-2021-1647 is a remote code execution flaw in Microsoft Defender, the built-in antivirus and endpoint protection component of Windows, as well as Security Essentials and System Center Endpoint Protection. The record provides only a generic description and no root-cause detail, but the flaw is serious because Defender runs with high privileges on nearly every Windows host and has been exploited in the wild.
Description
Microsoft Defender Remote Code Execution Vulnerability
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityThe flaw allows local code execution as a highly privileged service, is listed in CISA KEV as exploited in the wild, and has a high EPSS score, though it requires local access.
What it is
CVE-2021-1647 is a remote code execution flaw in Microsoft Defender, the built-in antivirus and endpoint protection component of Windows, as well as Security Essentials and System Center Endpoint Protection. The record provides only a generic description and no root-cause detail, but the flaw is serious because Defender runs with high privileges on nearly every Windows host and has been exploited in the wild.
Impact
A successful attacker gains code execution in the context of the Defender process, which typically runs with SYSTEM-level privileges, allowing full compromise of the host. The CVSS vector rates confidentiality, integrity and availability impact as high.
Attack surface
The CVSS vector is local (AV:L), low complexity (AC:L), low privileges required (PR:L) and no user interaction (UI:N), so the flaw is reached by a local actor or local process rather than over the network. No further detail on the exact entry point is given in the record.
Exploitation
The vulnerability is listed in CISA's Known Exploited Vulnerabilities catalog, indicating exploitation in the wild, and EPSS gives a 30-day exploitation probability of about 39% (98.5th percentile). No ransomware campaign use is documented.
What to do
- Apply the Microsoft security update referenced in the MSRC advisory for CVE-2021-1647 as the first action.
- Verify Defender platform and engine versions across all Windows, Security Essentials and System Center Endpoint Protection endpoints and force updates where automatic updating is disabled.
- Restrict local interactive and service-account access on endpoints to reduce the low-privilege local attack path.
- Monitor for unexpected Defender process behavior or crashes that could indicate exploitation attempts.
Detection
- Hunt for unusual child processes or code execution originating from MsMpEng.exe or other Defender binaries.
- Monitor Defender service crashes or restarts correlated with suspicious local activity.
- Review endpoint telemetry for local privilege escalation or process injection targeting Defender components.
- Track patch compliance for the MSRC update associated with CVE-2021-1647 across the fleet.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2021-1647 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Microsoft Defender Remote Code Execution Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 17 November 2021.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-1647 | PatchVendor Advisory |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-1647 | PatchVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-1647 | US Government Resource |
Track CVE-2021-1647 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-1647), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.