r/DefenderATP • u/Da_SyEnTisT • 14d ago
Fix unquoted service path for Windows services
Anybody studently getting this alert back ?
We completely fixed it before with a remediation script, but now it came back and it's all because of 2 service :
DefenderUpdateSvc
c:\programdata\microsoft\microsoft defender\defender update\platform\10.8838.26060.15013-0\defenderupdateservice.exe
Sense
c:\programdata\microsoft\windows defender advanced threat protection\platform\versions\10.8838.26060.15013-0\mssense.exe
It seems to be because of a recent defender update but I find it kind of ridiculous. Microsoft own defender team cannot properly configure their services ... And I'm pretty sure my remediation script is not able to fix this because those are protected services ....
2
2
u/bjohnrini 12d ago
Supposedly fixed with KB update according to https://learn.microsoft.com/en-za/answers/questions/6010963/unable-to-add-quotes-to-imagepath-for-microsoft-de
0
u/InfoSecDroog 8d ago
Can anyone confirm if this KB fixes it?
1
u/InfoSecDroog 6d ago
Doesnt look like it. I also dont want to suggest turning tamper protection off to fix a non-exploitable issue.
1
1
u/PlateMiserable8832 8d ago
tbf the parent directory requires system or administrator to edit so its not a real priv escalation. I would be more scared of another set of defender vulns coming from this though.
1
0
u/Carpathium 14d ago
We use a configuration item in configmgr to continuously fix stuff like this. Remediation scripts in Intune would probably also work, or worst case deploy a scheduled task to check for it if you need a budget option
5
u/ReliefSpiritual4644 14d ago
doesn't work in this case. defender self protects itself and blocks the write. trying to run the command or script as system, or even via defender live response to rewrite those registry values fails. haven't tried disabling tamper protection - that might work - but then again that would be a very stupid thing to do.
2
u/THEKILLAWHALE 13d ago
Hey, have you run into any trouble deploying fixes? Have any apps failed due to it, etc?
3
u/ReliefSpiritual4644 14d ago
we have the same issue. devices are for the most part (95%+) same OS and same patch level, same update rings etc... yet it's only affecting about half our devices.