Microsoft Defender Update Could Disable Protection On Linux Servers After Reboot
Microsoft released a fix for a bug in Defender for Endpoint on Linux that caused the security service to disable itself after a reboot. A secondary issue affecting Red Hat Enterprise Linux systems in FIPS mode was also addressed in a subsequent update.
Why it matters
Highlights the risks of automated security updates in enterprise environments and the importance of rigorous testing for Linux-based infrastructure.
Microsoft has fixed two defects in Defender for Endpoint on Linux after an update caused the security service to become disabled on some machines following a reboot and prevented installation on certain Red Hat Enterprise Linux systems configured to meet federal cryptographic requirements.
The more serious fault affected Defender for Endpoint platform builds 101.26042.0000 through 101.26042.0009 on every supported Linux distribution. Microsoft said the service could become disabled when an affected device was upgraded or Defender was reinstalled and the operating system was subsequently restarted.
The problem was particularly significant for organisations using Microsoft Defender for Servers through Defender for Cloud. In those environments, automatic updates for the MDE.Linux extension may be enabled by default, meaning vulnerable builds could have reached servers without administrators installing them manually.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in