Microsoft releases fix for botched Windows Defender update, but it's still facing problems

Microsoft Defender home personal dashboard
(Image credit: Microsoft)

There are only two ‘Friday the 13th’s in 2023, and the first has already seen Microsoft scrambling to fix an issue that affected users’ Start menus and taskbars following a botched update to its Defender antivirus.

Following the mishap, Microsoft took to the Internet to confirm that many users had experienced “a series of false positive detections” for the “Block Win32 API calls from Office macro” Attack Surface Reduction (ASR) rule, leading to many program shortcuts (.lnk files) vanishing.

Among the initially suggested fixes from the company was to turn the “Block Win32 API calls from Office macro” rule into audit mode, however Microsoft has now issued a more comprehensive fix that, after deploying, will allow users to turn the ASR rule back into block mode.

Microsoft Defender problem

The company has told users to upgrade to security intelligence build 1.381.2164.0 or later. An extract from the help page reads:

“Microsoft has confirmed steps that customers can take to recreate start menu links for a significant sub-set of the affected applications that were deleted.”

The steps have been provided as a PowerShell script on a GitHub page - a developer platform that Microsoft owns. There’s also a set of instructions for deploying the script using Intune, which many users were vocal about when it came to discussing the blunder on platforms like Reddit and Microsoft’s own Tech Community page.

One user asked Microsoft “why Defender did not record the lnk file deletions”.

As the problem continues to be an ongoing source of disruption among Microsoft users, it’s unclear whether the fix has been enough for the tech giant to restore some of its lost faith. Overall, user experiences remain a mixed bag, with some claiming successful restores, and others reporting errors.

TOPICS
Craig Hale

With several years’ experience freelancing in tech and automotive circles, Craig’s specific interests lie in technology that is designed to better our lives, including AI and ML, productivity aids, and smart fitness. He is also passionate about cars and the decarbonisation of personal transportation. As an avid bargain-hunter, you can be sure that any deal Craig finds is top value!

Read more
Angry businessman destroying his desk and laptop with a baseball bat
New patch for Windows 11 24H2 reportedly plays havoc with File Explorer, and some folks are claiming it's broken their PC
A man sitting at his computer desk on his desktop with his head in his hands, looking a little frustrated.
Windows 11 suffers more bugs in latest update, with the Start menu hit hard by some frustrating issues
A laptop with the Windows 11 desktop on screen, glowing, while on a work desk
Are you unable to get security updates for Windows 11 24H2? Here’s the likely reason why, and the fix to get your PC safe and secure again
A man getting angry with his laptop.
Windows 11 bug deletes Copilot from the OS – is this the first glitch ever some users will be happy to encounter?
Phone scammer
Microsoft thinks it could stop this dangerous scam forever
Man having Windows 11 problems with his laptop
Fed up of adverts creeping into Windows 11? You won’t like Microsoft’s latest update, then, although it does provide some important bug fixes
Latest in Security
Hacker silhouette working on a laptop with North Korean flag on the background
North Korea unveils new military unit targeting AI attacks
An image of network security icons for a network encircling a digital blue earth.
US government warns agencies to make sure their backups are safe from NAKIVO security issue
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
This top WordPress plugin could be hiding a worrying security flaw, so be on your guard
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
Veeam urges users to patch security issues which could allow backup hacks
UK Prime Minister Sir Kier Starmer
The UK releases timeline for migration to post-quantum cryptography
Representational image depecting cybersecurity protection
Cisco smart licensing system sees critical security flaws exploited
Latest in News
Google Pixel 9
The Google Pixel 10 just showed up in Android code – and may come with a useful speed boost
L-mount alliance
Sirui joins L-Mount Alliance to deliver its superb budget lenses for Leica, DJI, Sigma and Panasonic cameras
Security padlock and circuit board to protect data
Trust in digital services around the world sees a massive drop as security worries continue
A Lego Pikachu tail next to a Pebble OS watch and a screenshot of Assassin's Creed Shadow
ICYMI: the week's 7 biggest tech stories from LG's excellent new OLED TV to our Assassin's Creed Shadow review
Samuel and Romy standing very close together in A24's Babygirl movie
Everything new on Max in April 2025, including A24's Babygirl and The Last of Us season 2
An AMD Radeon RX 9070 XT made by Sapphire on a table with its retail packaging
AMD’s secret weapon against Nvidia seems to be stock – way more RX 9070 GPUs are rumored to be hitting shelves than RTX 5000 models