← Vulnerability feed

Vulnerability record · CVE-2021-1647 · published 12 January 2021

CVE-2021-1647: Microsoft Defender Remote Code Execution Vulnerability

Microsoft · Windows Defender

CVE-2021-1647 is a remote code execution flaw in Microsoft Defender, the built-in antivirus and endpoint protection component of Windows, as well as Security Essentials and System Center Endpoint Protection. The record provides only a generic description and no root-cause detail, but the flaw is serious because Defender runs with high privileges on nearly every Windows host and has been exploited in the wild.

7.8 CVSS 3.1 High CISA KEV since 3 Nov 2021 EPSS 39% · top 1.4%
7.8CVSS 3.1 base score, v2 7.2
39%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
3Affected product versions listed by NVD
3References
17 Jun 2026Last modified by NVD

Description

Microsoft Defender Remote Code Execution Vulnerability

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: medium.

high priorityThe flaw allows local code execution as a highly privileged service, is listed in CISA KEV as exploited in the wild, and has a high EPSS score, though it requires local access.

What it is

CVE-2021-1647 is a remote code execution flaw in Microsoft Defender, the built-in antivirus and endpoint protection component of Windows, as well as Security Essentials and System Center Endpoint Protection. The record provides only a generic description and no root-cause detail, but the flaw is serious because Defender runs with high privileges on nearly every Windows host and has been exploited in the wild.

Impact

A successful attacker gains code execution in the context of the Defender process, which typically runs with SYSTEM-level privileges, allowing full compromise of the host. The CVSS vector rates confidentiality, integrity and availability impact as high.

Attack surface

The CVSS vector is local (AV:L), low complexity (AC:L), low privileges required (PR:L) and no user interaction (UI:N), so the flaw is reached by a local actor or local process rather than over the network. No further detail on the exact entry point is given in the record.

Exploitation

The vulnerability is listed in CISA's Known Exploited Vulnerabilities catalog, indicating exploitation in the wild, and EPSS gives a 30-day exploitation probability of about 39% (98.5th percentile). No ransomware campaign use is documented.

What to do

  • Apply the Microsoft security update referenced in the MSRC advisory for CVE-2021-1647 as the first action.
  • Verify Defender platform and engine versions across all Windows, Security Essentials and System Center Endpoint Protection endpoints and force updates where automatic updating is disabled.
  • Restrict local interactive and service-account access on endpoints to reduce the low-privilege local attack path.
  • Monitor for unexpected Defender process behavior or crashes that could indicate exploitation attempts.

Detection

  • Hunt for unusual child processes or code execution originating from MsMpEng.exe or other Defender binaries.
  • Monitor Defender service crashes or restarts correlated with suspicious local activity.
  • Review endpoint telemetry for local privilege escalation or process injection targeting Defender components.
  • Track patch compliance for the MSRC update associated with CVE-2021-1647 across the fleet.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2021-1647 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Microsoft Defender Remote Code Execution Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 17 November 2021.

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-1647 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2017-8540Microsoft Malware Protection Engine out-of-bounds write via crafted fileThe Microsoft Malware Protection Engine, used by Windows Defender, Forefront, Security Essentials, System Center Endpoint Protection, Intune Endpoint…KEVEPSS 72%analysed9.3CVE-2006-5270Microsoft antigen vulnerabilityInteger overflow in the Microsoft Malware Protection Engine (mpengine.dll), as used by Windows Live OneCare, Antigen, Defender, and Forefront Securit…EPSS 30%8.8CVE-2018-0986Microsoft Malware Protection Engine out-of-bounds write enables remote code executionThe Microsoft Malware Protection Engine mishandles a specially crafted file during scanning, causing an out-of-bounds write and memory corruption. Be…EPSS 63%analysed7.8CVE-2023-36422Microsoft windows defender untrusted search path vulnerabilityMicrosoft Windows Defender Elevation of Privilege VulnerabilityEPSS 0.81%7.8CVE-2023-38175Microsoft windows defender link following vulnerabilityMicrosoft Windows Defender Elevation of Privilege VulnerabilityEPSS 0.54%7.8CVE-2021-24092Microsoft windows defender improper privilege management vulnerabilityMicrosoft Defender Elevation of Privilege VulnerabilityEPSS 0.61%7.8CVE-2020-1163Microsoft windows defender vulnerabilityAn elevation of privilege vulnerability exists in Windows Defender that leads arbitrary file deletion on the system.To exploit the vulnerability, an …EPSS 0.89%7.8CVE-2020-1170Microsoft windows defender incorrect permission assignment vulnerabilityAn elevation of privilege vulnerability exists in Windows Defender that leads arbitrary file deletion on the system.To exploit the vulnerability, an …EPSS 1.6%

Source: NIST National Vulnerability Database (record CVE-2021-1647), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.