How to Fix CVE-2018-0986 [ Microsoft Malware Protection Engine Remote Code Execution Vulnerability] from BigFix, I dont see any Fixlet for it

We just published the Defender update, Content Modification: Updates for Windows Applications Extended published 2023-07-26

Currently we test that Defender is enabled to begin with, so it will probably be not relevant by default on your machines. We’re not sure the update could even deploy with Defender disabled and prefer to err on the side of caution.

You could custom-copy the fixlet and remove Relevance 6 that checks the protection has not been disabled, and see whether the update clears your false-positive status. If the update can run on systems with Defender disabled, we could tweak that relevance.

1 Like