Microsoft Defender False Positive Flags DigiCert Root Certificates as Malware

On April 30, Microsoft Defender incorrectly flagged two DigiCert root certificates as malware. The false positive labeled the certificates as Trojan:Win32/Cerdigent.A!dha. Overly broad detection logic caused the false positive The affected certificates are the DigiCert Assured ID Root CA and the DigiCert Trusted Root G4. Microsoft said the false positive was caused by overly broad […]

Microsoft Defender False Positive Flags DigiCert Root Certificates as Malware
Abstract modern background of blue flowing lines

On April 30, Microsoft Defender incorrectly flagged two DigiCert root certificates as malware. The false positive labeled the certificates as Trojan:Win32/Cerdigent.A!dha.

Overly broad detection logic caused the false positive

The affected certificates are the DigiCert Assured ID Root CA and the DigiCert Trusted Root G4. Microsoft said the false positive was caused by overly broad detection logic after a real incident involving compromised EV code-signing certificates from DigiCert.

Microsoft fixed the issue with a security intelligence update

Microsoft fixed the issue in Security Intelligence update 1.449.430.0. Some users reported still seeing the alert on definition version 1.449.446.0, but Microsoft has not officially confirmed that.

Microsoft told BleepingComputer that it determined the false positive alerts were mistakenly triggered and updated the alert logic.

Discussion

0 comments

Log in to join the thread with a thoughtful take, question, or correction.

Add to the discussion