Microsoft downplays alarm over Windows Defender 'flaw'

The revelation...

is that Defender doesn't scan the executable as it is loaded by CreateProcess, but separately opens the file, scans the data it finds, then allows CreateProcess to continue.

This is ripe for exploitation by anything tyhat can also hook file system reads.

