业界动态
Microsoft Defender Antivirus security intelligence and product updates
2024-07-31 21:53

Applies to:

  • Microsoft Defender for Endpoint Plans 1 and 2
  • Microsoft Defender Antivirus

Platforms

  • Windows

Keeping Microsoft Defender Antivirus up to date is critical to assure your devices have the latest technology and features needed to protect against new malware and attack techniques. Update your antivirus protection, even if Microsoft Defender Antivirus is running in passive mode. This article includes information about the two types of updates for keeping Microsoft Defender Antivirus current:

  • Security intelligence updates
  • Product updates

This article also includes:

  • Microsoft Defender Antivirus platform support
  • How to roll back an update (if necessary)
  • Platform version included with Windows 10 releases
  • Updates for Deployment Image Servicing and Management (DISM)

To see the most current engine, platform, and signature date, see Security intelligence updates for Microsoft Defender Antivirus and other Microsoft antimalware.

Microsoft Defender Antivirus uses cloud-delivered protection (also called the Microsoft Advanced Protection Service, or MAPS) and periodically downloads dynamic security intelligence updates to provide more protection. These dynamic updates don't take the place of regular security intelligence updates via security intelligence update KB2267602.

Cloud-delivered protection is always on and requires an active connection to the Internet to function. Security intelligence updates occur on a scheduled cadence (configurable via policy). For more information, see Use Microsoft cloud-provided protection in Microsoft Defender Antivirus.

For a list of recent security intelligence updates, see Security intelligence updates for Microsoft Defender Antivirus and other Microsoft antimalware.

Engine updates are included with security intelligence updates and are released on a monthly cadence.

Microsoft Defender Antivirus requires monthly updates (KB4052623) known as platform updates.

You can manage the distribution of updates through one of the following methods:

  • Windows Server Update Service (WSUS)
  • Microsoft Configuration Manager
  • The usual methods you use to deploy Microsoft and Windows updates to endpoints in your network.

For more information, see Manage the sources for Microsoft Defender Antivirus protection updates.

  • Monthly updates are released in phases, resulting in multiple packages visible in your Window Server Update Services.

  • This article lists changes that are included in the broad release channel. See the latest broad channel release here.

  • To learn more about the gradual rollout process, and to see more information about the next release, see Manage the gradual rollout process for Microsoft Defender updates.

  • To learn more about security intelligence updates, see Security intelligence updates for Microsoft Defender Antivirus and other Microsoft antimalware.

  • If you're looking for a list of Microsoft Defender processes, see the spreadsheet provided at Enable access to Microsoft Defender for Endpoint service URLs in the proxy server. The sheet also lists the services and their associated URLs that your network must be able to connect to.

  • Platform updates can be temporarily postponed if other protection features, such as Endpoint DLP or Device Control are actively monitoring running processes. Platform updates are retried after a reboot or when all monitored services are stopped.

  • In the Microsoft Endpoint Configuration Manager / Windows Server Update Services (MECM/WSUS) catalog, the category Microsoft Defender for Endpoint includes updates for the MSSense service in KB5005292. KB5005292 includes updates and fixes to the Microsoft Defender for Endpoint endpoint detection and response (EDR) sensor. For more information, see Microsoft Defender for Endpoint update for EDR Sensor and What's new in Microsoft Defender for Endpoint on Windows.

All our updates contain:

  • Performance improvements
  • Serviceability improvements
  • Integration improvements (Cloud, Microsoft Defender XDR)
  • Security intelligence update version: 1.415.1.0
  • Release date: July 9, 2024 (Engine) / July 15, 2024 (Platform)
  • Platform: 4.18.24060.7
  • Engine: 1.1.24060.5
  • Support phase: Security and Critical Updates
  • Fixed issue where Microsoft Defender Antivirus was not properly changing state when non-Microsoft antivirus/antimalware software was installed and Windows Defender Application Control (WDAC) with Intelligent Security Graph were enabled.
  • Fixed deadlock issue on VDI that occurred when loading corrupted update files from UNC share.
  • Custom scans started with Start-MpScan are now reported in the event log.
  • Fixed potential deadlock that occurred on volume mount scanning.
  • Fixed issue where Microsoft Defender Antivirus did not allow applications to clean up temporary files.
  • Fixed potentially packet loss due to network protection shutdown that could lead to deadlock.
  • Implemented performance improvements for scenarios where WDAC is enabled with Intelligent Security Graph.
  • Fixed an issue where an Outlook exclusion for the ASR rule Block Office applications from injecting code into other processes was not honored.
  • Fixed a race condition during the startup of endpoint data loss prevention such that, in certain environments, some system files could be corrupted.
  • Security intelligence update version: 1.413.1.0
  • Release date: May 30, 2024 (Engine) / June 4, 2024 (Platform)
  • Engine: 1.1.24050.5
  • Platform: 4.18.24050.7
  • Support phase: Security and Critical Updates

What's new

  • Improved performance when running configuration queries.
  • Optimized how scans are prioritized.
  • Fixed a crash caused by a race condition with a device control driver.
  • Added Event Viewer Logging for scan start event where the scan originates from PowerShell.
  • Security intelligence update version: 1.411.7.0
  • Release date: May 07, 2024 (Engine) / May 16, 2024 (Platform)
  • Engine: 1.1.24040.1
  • Platform: 4.18.24040.4
  • Support phase: Security and Critical Updates

What's new

  • Added an opt-out feature for Experimental Configuration Services (ECS) and One collector in the Core Service.
  • Fixed an issue where occasionally exclusions deployed via Intune were not being honored when tamper protection was enabled.
  • After a new engine version is released, support for older versions (N-2) will now reduce to technical support only. Engine versions older than N-2 are no longer supported.
  • Improved health monitoring and telemetry for attack surface rules exclusions.
  • Updated inaccurate information in Configure exclusions for files opened by processes regarding wildcard usage with contextual exclusions.

After a new package version is released, support for the previous two versions is reduced to technical support only. For more information about previous versions, see Microsoft Defender Antivirus updates: Previous versions for technical upgrade support.

Platform and engine updates are provided on a monthly cadence. To be fully supported, keep current with the latest platform and engine updates. Our support structure is dynamic, evolving into two phases depending on the availability of the latest platform and engine version:

  • Security and Critical Updates servicing phase - When running the latest platform and engine version, you're eligible to receive both Security and Critical updates to the anti-malware platform.

  • Technical Support (Only) phase - After a new platform and engine version is released, support for older versions (N-2) reduce to technical support only. Platform and engine versions older than N-2 are no longer supported. Technical support continues to be provided for upgrades from the Windows 10 release version (see Platform version included with Windows 10 releases) to the latest platform version.

During the technical support (only) phase, commercially reasonable support incidents are provided through Microsoft Customer Service & Support and Microsoft's managed support offerings (such as Premier Support). If a support incident requires escalation to development for further guidance, requires a nonsecurity update, or requires a security update, customers are asked to upgrade to the latest platform version or an intermediate update (*).

In the unfortunate event that you encounter issues after a platform update, you can roll back to the previous or the inbox version of the Microsoft Defender platform.

  • To roll back to the previous version, run the following command:

  • To roll back this update to the version shipped with the Operating System ("%ProgramFiles%Windows Defender")

The below table provides the Microsoft Defender Antivirus platform and engine versions that are shipped with the latest Windows 10 releases:

Windows 10 release Platform version Engine version Support phase 2004 (20H1/20H2) Technical upgrade support (only) 1909 (19H2) Technical upgrade support (only) 1903 (19H1) Technical upgrade support (only) 1809 (RS5) Technical upgrade support (only) 1803 (RS4) Technical upgrade support (only) 1709 (RS3) Technical upgrade support (only) 1703 (RS2) Technical upgrade support (only) 1607 (RS1) Technical upgrade support (only)

For Windows 10 release information, see the Windows lifecycle fact sheet.

To avoid a gap in protection, keep your OS installation images up to date with the latest antivirus and antimalware updates. Updates are available for:

  • Windows 10 and 11 (Enterprise, Pro, and Home editions)
  • Windows Server 2022, Windows Server 2019, Windows Server 2016, and Windows Server 2012 R2
  • WIM and VHD(x) files

Updates are released for x86, x64, and ARM64 Windows architecture.

For more information, see Microsoft Defender update for Windows operating system installation images.

After a new package version is released, support for the previous two versions is reduced to technical support only.

  • Defender package version:
  • Security intelligence version:
  • Engine version:
  • Platform version:

Fixes

  • None

Additional information

  • None
  • Defender package version:
  • Security intelligence version:
  • Engine version:
  • Platform version:

Fixes

  • None

Additional information

  • None
  • Defender package version:
  • Security intelligence version:
  • Engine version:
  • Platform version:

Fixes

  • None

Additional information

  • None
Article Description Microsoft Defender update for Windows operating system installation images Review antimalware update packages for your OS installation images (WIM and VHD files). Get Microsoft Defender Antivirus updates for Windows 10 (Enterprise, Pro, and Home editions), Windows Server 2019, Windows Server 2022, Windows Server 2016, and Windows Server 2012 R2 installation images. Manage how protection updates are downloaded and applied Protection updates can be delivered through many sources. Manage when protection updates should be downloaded and applied You can schedule when protection updates should be downloaded. Manage updates for endpoints that are out of date If an endpoint misses an update or scheduled scan, you can force an update or scan the next time a user signs in. Manage event-based forced updates You can set protection updates to be downloaded at startup or after certain cloud-delivered protection events. Manage updates for mobile devices and virtual machines (VMs) You can specify settings, such as whether updates should occur on battery power that 's especially useful for mobile devices and virtual machines. Microsoft Defender for Endpoint update for EDR Sensor You can update the EDR sensor (MsSense.exe) that's included in the new Microsoft Defender for Endpoint unified solution package released in 2021.
    以上就是本篇文章【Microsoft Defender Antivirus security intelligence and product updates】的全部内容了,欢迎阅览 ! 文章地址:http://www78564.xrbh.cn/news/13969.html 
     文章      相关文章      动态      同类文章      热门文章      栏目首页      网站地图      返回首页 迅博思语移动站 http://www78564.xrbh.cn/mobile/ , 查看更多   
最新文章
陶然|推动改革,不仅需要政策支持也需要敢做试点的地方支持
受访人|陶然  香港中文大学(深圳)人文社科学院校长讲座教授,发展与治理学科部主任,发展与治理研究院院长访谈人|吴晨  “
曝京东大型折扣超市将落地:面积可达5000平米
8月5日消息,据媒体报道,近日,京东在下沉市场又爆出新动作,8月份将在江苏宿迁、河北涿州两地五店同开,落地京东折扣超市。区
后天直冲44℃!重庆再发高温红色预警,健康风险提醒请查收
【来源:重庆晨报】8月2日11时40分,重庆市气象台发布“高温红色预警信号”:预计2日13:00-20:00,渝中、沙坪坝、大渡口、江北、
发霉飞天茅台酒全国回收价格2025年参数
发霉飞天茅台酒全国回收价格2025年参数海淀区、东城区、西城区、宣武区、丰台区、朝阳区、崇文区、大兴区、石景山区、门头沟区、
李会宁:立足“一岗双责” 积极履职
身为一名基层检察官,同时肩负着综合业务部主任的职责,我深刻体悟,“以人民为中心”不仅是我们工作的出发点,更是检察履职的根
原创48小时内,中美日局势大变,特朗普处境不妙,日本已偷偷背刺美国
最近,原本被白宫称为“世纪大单”的美日投资协议,在热度尚未褪去之前,就迅速产生了变数。日本方面突然调整态度,澄清资金的性
北京:行政区全域划定为无人驾驶航空器管制空域
观点网讯:8月4日,北京市人民政府依据《无人驾驶航空器飞行管理暂行条例》第十九条,正式发布通告,将北京市行政区全域划定为无
河源去三亚天涯海角网红打卡地,到底值不值得跑一趟?避坑指南+热门新玩法大公开!
嘿朋友!我是老陈一个周末喜爱到处跑的旅行爱好者,最近有朋友问我 这难题问得我直挠头,因为确实值得但也确实有坑,今天就以过
四川江油通报14岁女孩被殴打案件 律师解读
2025年7月22日下午3点左右,四川江油市15岁的刘某甲因与14岁的赖某某有矛盾,便邀约13岁的刘某乙和14岁的彭某某对赖某某进行辱骂
揭东:不断提升城市品质 持续增进民生福祉
近日,记者驱车行驶在揭东区滨江路上,清风徐徐,送来道路两旁绿植的清新气息,阳光透过繁茂枝叶的缝隙,撒下细碎光影,为这条道