{"id":293094,"date":"2024-12-16T15:25:12","date_gmt":"2024-12-16T14:25:12","guid":{"rendered":"https:\/\/sftarticles.wpenginepowered.com\/es\/?p=345766"},"modified":"2025-07-01T15:37:32","modified_gmt":"2025-07-01T22:37:32","slug":"microsoft-fixes-a-serious-security-issue-that-affected-windows-defender","status":"publish","type":"post","link":"https:\/\/cms-articles.softonic.io\/en\/microsoft-fixes-a-serious-security-issue-that-affected-windows-defender\/","title":{"rendered":"Microsoft fixes a serious security issue that affected Windows Defender"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\"><strong>Microsoft<\/strong> has revealed a critical vulnerability in <strong>Windows Defender<\/strong> that could have allowed the exposure of sensitive data over a network. The security breach, identified as <strong><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/en-US\/vulnerability\/CVE-2024-49071\" target=\"_blank\" rel=\"noopener nofollow\" title=\"\">CVE-2024-49071<\/a><\/strong>, was made public on December 12 in the company&#8217;s security update guide. According to Microsoft, <strong>users do not need to take any action<\/strong>, as the solution was deployed remotely on the servers.<\/p>\n\n\n<div class=\"sc-card-starred-link\">\r\n  <div class=\"sc-card-starred-link__body\">\r\n    <div class=\"sc-card-starred-link__row clearfix\">\r\n      <div class=\"sc-card-starred-link__col-logo\">\r\n        <img decoding=\"async\" class=\"sc-card-starred-link__img\" src=\"https:\/\/articles-img.sftcdn.net\/sft\/articles\/auto-mapping-folder\/sites\/3\/2024\/09\/newsletter.png?GoogleAccessId=wp-stateless%40kubertonic.iam.gserviceaccount.com&Expires=1788979352&Signature=soXuILvQu%2BUHOFUAA8cnabI5TKVhNVzvsEsiwDBoIfsOugTmvDPvdHwRWAXY9j8Yn6eFzatjhhE%2FAMJKCckRlo9nITL9OVOA05U0SKz9eqhybTg0fBoWF%2FTrdc%2FhJz%2FnBmHmzSMU1ORII2%2FaQ6KorpNepBmzchDTlttkjA1gJFJmptFNPoMCtPA%2FvSSFkykrPmzXsBeYVSpyZ%2FNn%2BTjcw0Qqify9TBxlV2aOZQK6xuCg2sY%2Bh7Dl0HK0Pm3HzPo2DqdUFJf2uZ4D4NFkw0YLgGuFdaNFsxrnrHFEPQ4IiWS%2BHYu8OWShVRLtbPh%2FSSolxEbmxi7pONMjC%2BzQfmi9Yg%3D%3D\" width=\"100px\" height=\"100px\">\r\n      <\/div>\r\n      <div class=\"sc-card-starred-link__col-title\">\r\n        <p class=\"sc-card-starred-link__title\">Subscribe to the Softonic newsletter and get the latest in tech, gaming, entertainment and deals right in your inbox.<\/p>\r\n        <a class=\"sc-card-starred-link__button\" href=\"https:\/\/en.softonic.beehiiv.com\/subscribe\" target=\"_blank\" rel=\"noopener noreferrer sponsored\">Subscribe (it's FREE) \u25ba<\/a>\r\n      <\/div>\r\n    <\/div>\r\n    <a class=\"sc-card-starred-link__link\" href=\"https:\/\/en.softonic.beehiiv.com\/subscribe\" target=\"_blank\" rel=\"noopener noreferrer sponsored\"><\/a>\r\n  <\/div>\r\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">The problem was that <strong>Windows Defender created an \u201cindex of private or sensitive document searches\u201d without adequately limiting access to it<\/strong>. This, according to <a href=\"https:\/\/debricked.com\/vulnerability-database\/vulnerability\/CVE-2024-49071\" target=\"_blank\" rel=\"noopener nofollow\" title=\"\">the <strong>Debricked<\/strong> vulnerability database<\/a>, could have allowed unauthorized actors to access confidential information. Although the complexity of the attack was low, exploiting it required some prior access to Windows Defender. Fortunately, <strong>no cases of exploitation of this vulnerability have been reported so far<\/strong>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Microsoft has clarified that <strong>the vulnerability has already been completely fixed<\/strong> and that users do not need to install patches or make adjustments. This strategy, although unusual for a critical vulnerability, reflects <strong>a new approach by the company towards transparency in security matters<\/strong>. Since June 2024, Microsoft has committed to notifying users about critical vulnerabilities in cloud services, even when it is not necessary for them to take direct action.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full\"><img decoding=\"async\" src=\"https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/2\/2024\/09\/microsoft-seguridas.jpg\" alt=\"\" class=\"wp-image-340990\" \/><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">\u201cWe will issue CVEs for critical vulnerabilities in cloud services, regardless of whether customers need to install a patch or take other measures to protect themselves,\u201d <a href=\"https:\/\/msrc.microsoft.com\/blog\/2024\/06\/toward-greater-transparency-unveiling-cloud-service-cves\/\" target=\"_blank\" rel=\"noopener nofollow\" title=\"\">stated<\/a> Microsoft mid-year. This approach aims to strengthen trust in the company by proactively reporting on issues that have already been resolved.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In this case, Microsoft states that &#8220;the vulnerability documented by this CVE does not require any customer action to be resolved&#8221; and added that &#8220;it has already been fully mitigated.&#8221;<\/p>\n\n\n<div class=\"sc-card-program\">\r\n  <div class=\"sc-card-program__body\">\r\n    <div class=\"sc-card-program__row clearfix\">\r\n      <div class=\"sc-card-program__col-logo\">\r\n        <img decoding=\"async\" class=\"sc-card-program__img\" alt=\"Windows 11\" src=\"https:\/\/images.sftcdn.net\/images\/t_app-icon-s\/p\/3a83edc2-8bcb-4baa-8fbe-3ddcf458c1a4\/1709716978\/windows-11-win11icon.png\" width=\"100px\" height=\"100px\">\r\n      <\/div>\r\n      <div class=\"sc-card-program__col-title\">\r\n        <span class=\"sc-card-program__title\">Windows 11<\/span>\r\n        <a class=\"sc-card-program__button sc-card-program-internal\" href=\"https:\/\/windows-11.en.softonic.com\/\" target=\"_self\" rel=\"noopener noreferrer\">DOWNLOAD<\/a>\r\n      <\/div>\r\n      <div class=\"sc-card-program__col-rating\">\r\n        <svg class=\"rating-score__content\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" version=\"1.1\" x=\"0\" y=\"0\" viewbox=\"0 0 50 50\" enable-background=\"new 0 0 50 50\" xml:space=\"preserve\"><path class=\"rating-score__background rating-score--good\" fill=\"none\" stroke-width=\"6\" stroke-miterlimit=\"10\" d=\"M40 40c8.3-8.3 8.3-21.7 0-30s-21.7-8.3-30 0 -8.3 21.7 0 30\"><\/path><path class=\"rating-score__value rating-score__value--0\" fill=\"none\" stroke-width=\"6\" stroke-dashoffset=\"0\" stroke-miterlimit=\"10\" d=\"M40 40c8.3-8.3 8.3-21.7 0-30s-21.7-8.3-30 0 -8.3 21.7 0 30\"><\/path><text class=\"rating-score__number\" content=\"\" text-anchor=\"middle\" transform=\"matrix(1 0 0 1 25 31.0837)\" data-auto=\"app-user-score\"><\/text><\/svg>\r\n      <\/div>\r\n    <\/div>\r\n    <div class=\"sc-card-program__row\">\r\n      <span class=\"sc-card-program__description\"><\/span>\r\n    <\/div>\r\n    <div class=\"sc-card-program__row\">\r\n      <img decoding=\"async\" class=\"sc-card-program__bigpic\" src=\"\" onerror=\"this.style.display='none'\">\r\n    <\/div>\r\n    <a class=\"sc-card-program__link track-link sc-card-program-internal\" href=\"https:\/\/windows-11.en.softonic.com\/\" target=\"_self\" rel=\"noopener noreferrer\"><\/a>\r\n  <\/div>\r\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Microsoft has revealed a critical vulnerability in Windows Defender that could have allowed the exposure of sensitive data over a network. The security breach, identified as CVE-2024-49071, was made public on December 12 in the company&#8217;s security update guide. According to Microsoft, users do not need to take any action, as the solution was implemented remotely on the servers. The issue was that Windows Defender created an &#8220;index of private or sensitive document searches&#8221; without adequately limiting access to it. This, according to the database of [&hellip;]<\/p>\n","protected":false},"author":9256,"featured_media":293101,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","wpcf-pageviews":9},"categories":[1015],"tags":[],"usertag":[],"vertical":[],"content-category":[],"class_list":["post-293094","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/293094","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/users\/9256"}],"replies":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/comments?post=293094"}],"version-history":[{"count":1,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/293094\/revisions"}],"predecessor-version":[{"id":310436,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/293094\/revisions\/310436"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/media\/293101"}],"wp:attachment":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/media?parent=293094"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/categories?post=293094"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/tags?post=293094"},{"taxonomy":"usertag","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/usertag?post=293094"},{"taxonomy":"vertical","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/vertical?post=293094"},{"taxonomy":"content-category","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/content-category?post=293094"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}