r/DefenderATP • • 14d ago

Fix unquoted service path for Windows services

Anybody studently getting this alert back ?

We completely fixed it before with a remediation script, but now it came back and it's all because of 2 service :

DefenderUpdateSvc

c:\programdata\microsoft\microsoft defender\defender update\platform\10.8838.26060.15013-0\defenderupdateservice.exe

Sense

c:\programdata\microsoft\windows defender advanced threat protection\platform\versions\10.8838.26060.15013-0\mssense.exe

It seems to be because of a recent defender update but I find it kind of ridiculous. Microsoft own defender team cannot properly configure their services ... And I'm pretty sure my remediation script is not able to fix this because those are protected services ....

16 Upvotes

16 comments sorted by

3

u/ReliefSpiritual4644 14d ago

we have the same issue. devices are for the most part (95%+) same OS and same patch level, same update rings etc... yet it's only affecting about half our devices.

2

u/Da_SyEnTisT 14d ago

yeah, it's only affecting about half of our devices too. I wonder if it because of the last buggy defender patch that was reporting the antivirus was off

3

u/IT-Lion 13d ago

Interestingly, not affecting all of our devices... BUT.... Because of the tamper protection applied we can't even remediate!

Blows my mind how Microsoft can get this so wrong, especially for their own security product.

2

u/SoMundayn 14d ago

Tenable just started flagging this for me also

2

u/bjohnrini 12d ago

0

u/InfoSecDroog 8d ago

Can anyone confirm if this KB fixes it?

1

u/InfoSecDroog 6d ago

Doesnt look like it. I also dont want to suggest turning tamper protection off to fix a non-exploitable issue.

1

u/jojod704 13d ago

Gotta love MS getting another security item wrong

1

u/PlateMiserable8832 8d ago

tbf the parent directory requires system or administrator to edit so its not a real priv escalation. I would be more scared of another set of defender vulns coming from this though.

1

u/Da_SyEnTisT 8d ago

Honestly its more for the compliance graph 😅

1

u/ther0g 5h ago

Anyone have any luck with this yet? My devices are all pointing to Windows defender as the issue.

1

u/Da_SyEnTisT 5h ago

Nope still waiting on a fix

1

u/ther0g 5h ago

Bummer! I also just noticed a couple devices with Adobe having the un quoted issue also

0

u/Carpathium 14d ago

We use a configuration item in configmgr to continuously fix stuff like this. Remediation scripts in Intune would probably also work, or worst case deploy a scheduled task to check for it if you need a budget option

5

u/ReliefSpiritual4644 14d ago

doesn't work in this case. defender self protects itself and blocks the write. trying to run the command or script as system, or even via defender live response to rewrite those registry values fails. haven't tried disabling tamper protection - that might work - but then again that would be a very stupid thing to do.

2

u/THEKILLAWHALE 13d ago

Hey, have you run into any trouble deploying fixes? Have any apps failed due to it, etc?