Windows 10 antivirus is not a security threat, Microsoft says

(Image credit: Shutterstock)

Microsoft has denied claims that its home-built Windows 10 antivirus could be putting users at risk from online attack.

Doubts had been raised over the security of Windows Defender after Microsoft announced a new feature for the platform that would allow it to download files via the command line.

Some security experts had warned that doing so could mean Windows Defender becomes a vessel through which users might unknowingly download malicious files from the web.

Windows Defender

However Microsoft has now hit back at the claims, with a company spokesperson telling Forbes that, "Despite these reports, Microsoft Defender antivirus and Microsoft Defender ATP will still protect customers from malware. These programs detect malicious files downloaded to the system through the antivirus file download feature."

The company added that the feature could not be used to escalate privileges on Windows machines, despite researchers warning that any tool that widens the potential attack surface on any device needs to be watched carefully.

The controversy stems from the fact that experts were able to use the new command line tool (known as -DownloadFile command-line) as a local user to use the Microsoft Antimalware Service Command Line Utility to download a file from the internet with the following command: “MpCmdRun.exe -DownloadFile -url <url> -path <local-path>”.

Using this technique, one expert (penetration tester Mohammad Askar) was able to download Cobalt Strike malware from a remote location directly via Microsoft Defender, showing the potential risks, despite the company's reply.

While Defender will detect and mitigate any malicious files downloaded using this method, it is unclear whether other popular antivirus services will be able to defend against this avenue of attack, in instances in which native protections have been disabled.

The news comes shortly after Microsoft was also criticized for making it more difficult to manually disable Microsoft Defender in Windows 10, although the app should automatically turn itself off if it detects you're running another antivirus program.

Via Forbes

Mike Moore
Deputy Editor, TechRadar Pro

Mike Moore is Deputy Editor at TechRadar Pro. He has worked as a B2B and B2C tech journalist for nearly a decade, including at one of the UK's leading national newspapers and fellow Future title ITProPortal, and when he's not keeping track of all the latest enterprise and workplace trends, can most likely be found watching, following or taking part in some kind of sport.

Latest in Security
Woman shocked by online scam, holding her credit card outside
Cybercriminals used vendor backdoor to steal almost $600,000 of Taylor Swift tickets
Woman using iMessage on iPhone
UK government guidelines remove encryption advice following Apple backdoor spat
Cryptocurrencies
Ransomware’s favorite Russian crypto exchange seized by law enforcement
Wordpress brand logo on computer screen. Man typing on the keyboard.
Thousands of WordPress sites targeted with malicious plugin backdoor attacks
HTTPS in a browser address bar
Malicious "polymorphic" Chrome extensions can mimic other tools to trick victims
ransomware avast
Hackers spotted using unsecured webcam to launch cyberattack
Latest in News
MacBook Air mute key
The new M4 MacBook Air finally fixes an Apple keyboard annoyance that's been around for decades
A collage of Ellie and Joel in The Last of Us season 2
The Last of Us season 2's new trailer teases a huge showdown between Bella Ramsey's Ellie and Pedro Pascal's Joel, but the big moment I'm waiting for is still being held back
Apple iPhone 16 Pro Max REVIEW
New iPhone 17 Air leak may have revealed some key specs – and how it compares to the iPhone 17 Pro Max
Gaming with AI
I asked Gemini to play a text-based adventure game with me and the AI whisked me away to a word-based fantasy
Apple iPhone 16 Review
Three iPhone 17 model dummy units appear in a hands-on video leak
The Samsung Galaxy S25 Edge on display the January 22, 2025 Galaxy Unpacked event.
New Samsung Galaxy S25 Edge may have revealed some key details – including its price