Several developers have come to Windows Defender's defense, highlighting its overall behavior and its non-interference policy with other security measures. However, that does not make it invulnerable to bugs, and Google's Project Zero just found one of the biggest. With just an email or a text message, the Windows Defender engine can be tricked into executing remote code, an extremely serious situation due to the high level of privileges this software has in the operating system.
A vulnerable antivirus is something very serious. What can the average user do when their main line of defense has more holes than Swiss cheese? There are not a few who suggest abandoning antiviruses altogether, but the latest versions of Windows come with one built in. Now, Windows Defender has received very good reviews from developers, especially those who work on web browsers. The latest generations of malware forced traditional antiviruses to implement changes that are not always positive for the performance and security of our machines, but Windows Defender is recognized as one of the most balanced. Unfortunately, that does not prevent errors in its code, and according to Google's Project Zero, the latest to appear is gigantic.
According to the data published by Natalie Silvanovich and Tavis Ormandy, the exploit identified as CVE-2017-0290 allows an attacker to take control of the computer without any kind of intervention from the local user. The only required step is to send an email, text message or web link prepared to fool the Windows Defender detection engine, which automatically scans the received content. This enables remote code execution, and presents the possibility of chaining attacks that move from one vulnerable computer to another.
Fortunately, any previous difference between Project Zero and Microsoft's development team is behind us. Redmond's response was immediate, and once they confirmed the severity of the exploit, they started working. It is most likely that you have already received the hotfix: All you need to do to confirm it is to go to Windows Defender options and verify that the minimum engine version is 1.1.13704.0. The affected versions of Windows are 7, 8.x, RT, 10, and Server 2016. If Windows Defender is your current antivirus, don't leave this for later.
Official announcement (Project Zero): https://bugs.chromium.org/p/project-zero/issues/detail?id=1252&desc=5
Official announcement (Microsoft): https://technet.microsoft.com/en-us/library/security/4022344