Defender Platform and Unquoted Service Path

ZaMMer-9504 0 Reputation points
2023-11-26T16:43:24.22+00:00

Seems the most recent version of defender platform and the last few versions have an un quoted service path issue that is not fixable on the user's side. Don't see anything in the changelog for this fix. Please have someone advise how to fix or if a platform update will be released that fixes this.

Nessus found the following service with an untrusted path : 
  MDCoreSvc : C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23110.3-0\MpDefenderCoreService.exe
Windows for business | Windows Client for IT Pros | User experience | Other
{count} votes

1 answer

Sort by: Most helpful
  1. abbodi86 4,841 Reputation points
    2023-11-27T04:34:37.32+00:00

    While it's bad practice, but i tracked the service starting using Procmon, services.exe checks "C:\ProgramData\Microsoft\Windows" folder, but it doesn't not try to load anything from there, it only load the specified service path for MpDefenderCoreService.exe


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.