Edit

Share via


Microsoft Defender Antivirus security intelligence and product updates

Keeping Microsoft Defender Antivirus up to date is critical to assure your devices are protected against new malware and attack techniques. Update your antivirus protection, even if Microsoft Defender Antivirus is running in passive mode. You can find the lates engine, platform, and signature date in Security intelligence updates for Microsoft Defender Antivirus and other Microsoft anti-malware

This article is aimed at Windows devices, and includes information about the following two types of updates:

Security intelligence updates

Microsoft Defender Antivirus uses cloud-delivered protection, also known as Microsoft Advanced Protection Service, or MAPS. Defender Antivirus periodically downloads dynamic security intelligence updates. These updates don't replace regular security intelligence updates. Engine updates are included with security intelligence updates and are released monthly.

Updates are released under the following KBs:

  • Microsoft Defender Antivirus: KB2267602

  • System Center Endpoint Protection: KB2461484

Cloud-delivered protection is always on and requires an active connection to the internet to function. Security intelligence updates occur on a scheduled cadence which you can configure using a policy.

Product updates

Microsoft Defender Antivirus requires monthly updates (KB4052623) known as platform updates.

You can manage the distribution of updates using one of the following methods:

For more information, see Manage the sources for Microsoft Defender Antivirus protection updates.

Important points about product updates

Platform and engine releases

Updates contain:

  • Performance improvements
  • Serviceability improvements
  • Integration improvements (Cloud, Microsoft Defender XDR)

September-2025 (Platform: 4.18.25090.3009 | Engine: 1.1.25090.3001)

  • Security intelligence update version: 1.439.345.0

  • Release date: October 8, 2025 (Engine) / October 21, 2025 (Platform)

  • Platform: 4.18.25090.3009

  • Engine: 1.1.25090.3001

  • Support phase: Security and Critical Updates

What's new

  • Improved service startup behavior: The core service now only restarts when necessary, for example, during a successful platform update. This change allows the organization to avoid unnecessary restarts when the service is already running correctly.
  • Improved stability for RPC services: Added input validation across multiple RPC endpoints to prevent crashes caused by malformed data, which addresses a reported security vulnerability.
  • Fixed threat exclusion handling: Resolved an issue where severity-based exclusions could cause the engine to misidentify threats, potentially skipping high severity detections.
  • Restored performance optimization for network file access: Fixed a regression that caused slowdowns during file operations, like robocopy to network shares. The fix included reintroducing the logic to skip unnecessary checks on non-local files when Controlled Folder Access is enabled.

August-2025 (Platform: 4.18.25080.5 | Engine: 1.1.25080.5)

  • Security intelligence update version: 1.437.1.0
  • Release date: September 16, 2025 (Engine) / September 17, 2025 (Platform)
  • Platform: 4.18.25080.5
  • Engine: 1.1.25080.5
  • Support phase: Security and Critical Updates

What's new

Improved Defender update reliability by allowing non-admin processes to trigger shared signature updates, reducing unnecessary privilege requirements.

Previous version updates: Technical upgrade support only

After a new package version is released, support for the previous two versions is reduced to technical upgrade support only. For more information about previous versions, see Microsoft Defender Antivirus updates: Previous versions for technical upgrade support.

Microsoft Defender Antivirus platform and engine support

Platform and engine updates are provided on a monthly cadence. To be fully supported, keep current with the latest platform and engine updates. Our support structure is dynamic, evolving into two phases depending on the availability of the latest platform and engine version:

  • Security and Critical Updates servicing phase - When running the latest platform and engine version, you're eligible to receive both Security and Critical updates to the anti-malware platform.

  • Technical Upgrade Support (Only) phase - After a new platform and engine version is released, support for older versions (N-2) reduce to technical upgrade support only. Platform and engine versions older than N-2 are no longer supported. Technical upgrade support continues to be provided for upgrades from the Windows 10 release version (see Platform version included with Windows 10 releases) to the latest platform version.

During the technical upgrade support (only) phase, commercially reasonable support incidents are provided through Microsoft Customer Service & Support and Microsoft's managed support offerings (such as Premier Support). If a support incident requires escalation to development for further guidance, requires a nonsecurity update, or requires a security update, customers are asked to upgrade to the latest platform version or an intermediate update (*).

Note

If you're manually deploying Microsoft Defender Antivirus Platform Update, or if you're using a script or a non-Microsoft management product to deploy Microsoft Defender Antivirus Platform Update, make sure that version 4.18.2001.10 is installed from the Microsoft Update Catalog before the latest version of Platform Update (N-2) is installed.

How to install an update

To install the latest security intelligence and antivirus engine updates, you can use any of the following methods:

  • Windows Update
  • Windows Update server (WSUS)
  • Software Update Point (SUP)
  • File server
  • Windows Security app: See Microsoft Defender Antivirus in the Windows Security app
  • Command line, as follows:
    • "%programdata%\Microsoft\Windows Defender\Platform\<version>\MpCmdRun.exe" -SignatureUpdate
    • "%programdata%\Microsoft\Windows Defender\Platform\<version>\MpCmdRun.exe" -SignatureUpdate \\FileServer\ShareName
    • "%programdata%\Microsoft\Windows Defender\Platform\<version>\MpCmdRun.exe" -SignatureUpdate -MMPC

For more information, see Manage the sources for Microsoft Defender Antivirus protection updates.

To get the latest platform updates, you can use any of the following methods:

How to roll back an update

In the unfortunate event that you encounter issues after an update, you can roll back to the previous or the inbox version.

Scenario Command
Roll security intelligence updates back to the previous or to the original inbox version of the security intelligence version "%programdata%\Microsoft\Windows Defender\Platform\<version>\MpCmdRun.exe"-RemoveDefinitions
Roll the engine version back to the previous version "%programdata%\Microsoft\Windows Defender\Platform\<version>\MpCmdRun.exe"-RemoveDefinitions -Engine
Roll a platform update back to the previous version "%programdata%\Microsoft\Windows Defender\Platform\<version>\MpCmdRun.exe" -RevertPlatform
Roll updates back to the version shipped with the operating system (%ProgramFiles%\Windows Defender) "%programdata%\Microsoft\Windows Defender\Platform\<version>\MpCmdRun.exe" -ResetPlatform

Platform version included with Windows 10 releases

The table provides the Microsoft Defender Antivirus platform and engine versions that are shipped with the latest Windows 10 releases:

Windows 10 release Platform version Engine version Support phase
2004 (20H1/20H2) 4.18.1909.6 1.1.17000.2 Technical upgrade support (only)
1909 (19H2) 4.18.1902.5 1.1.16700.3 Technical upgrade support (only)
1903 (19H1) 4.18.1902.5 1.1.15600.4 Technical upgrade support (only)
1809 (RS5) 4.18.1807.5 1.1.15000.2 Technical upgrade support (only)
1803 (RS4) 4.13.17134.1 1.1.14600.4 Technical upgrade support (only)
1709 (RS3) 4.12.16299.15 1.1.14104.0 Technical upgrade support (only)
1703 (RS2) 4.11.15603.2 1.1.13504.0 Technical upgrade support (only)
1607 (RS1) 4.10.14393.3683 1.1.12805.0 Technical upgrade support (only)

For Windows 10 release information, see the Windows lifecycle fact sheet.

Note

Windows Server 2016 ships with the same Platform version as RS1 and falls under the same support phase: Technical upgrade support (only)
Windows Server 2019 ships with the same Platform version as RS5 and falls under the same support phase: Technical upgrade support (only)

Updates for Deployment Image Servicing and Management (DISM)

To avoid a gap in protection, keep your OS installation images up to date with the latest antivirus and anti-malware updates. Updates are available for:

  • Windows 10 and 11 (Enterprise, Pro, and Home editions)
  • Windows Server 2012 R2 and later
  • Azure Stack HCI OS, version 23H2 and later
  • WIM and VHD(x) files

Updates are released for x86, x64, and Arm64 Windows architecture.

For more information, see Microsoft Defender update for Windows operating system installation images.

After a new package version is released, support for the previous two versions is reduced to technical support only. To view a list of previous versions, see Previous DISM updates.

1.431.97.0

  • Defender version: 1.431.97.0
  • Security intelligence version: 1.431.97.0
  • Platform version: 4.18.25050.5
  • Engine version: 1.25050.6

Fixes

  • None

Additional information

  • None

1.431.54.0

  • Defender version: 1.431.54.0
  • Security intelligence version: 1.431.54.0
  • Platform version: 4.18.25050.5
  • Engine version: 1.25050.2

Fixes

  • None

Additional information

  • None

1.429.122.0

  • Defender version: 1.429.122.0
  • Signature version: 1.429.122.0
  • Platform version: 4.18.25040.2
  • Engine version: 1.25040.1

Fixes

  • None

Additional information

  • None

More resources

Article Description
Microsoft Defender update for Windows operating system installation images Review anti-malware update packages for your OS installation images (WIM and VHD files). Get Microsoft Defender Antivirus updates for Windows 10 (Enterprise, Pro, and Home editions), Windows Server 2019, Windows Server 2022, Windows Server 2016, and Windows Server 2012 R2 installation images.
Manage how protection updates are downloaded and applied Protection updates can be delivered through many sources.
Manage when protection updates should be downloaded and applied You can schedule when protection updates should be downloaded.
Manage updates for endpoints that are out of date If an endpoint misses an update or scheduled scan, you can force an update or scan the next time a user signs in.
Manage event-based forced updates You can set protection updates to be downloaded at startup or after certain cloud-delivered protection events.
Manage updates for mobile devices and virtual machines (VMs) You can specify settings, such as whether updates should occur on battery power that's especially useful for mobile devices and virtual machines.
Microsoft Defender for Endpoint update for EDR Sensor You can update the EDR sensor (MsSense.exe) that's included in the new Microsoft Defender for Endpoint unified solution package released in 2021.

Tip

Do you want to learn more? Engage with the Microsoft Security community in our Tech Community: Microsoft Defender for Endpoint Tech Community.