I think it's only became like that after the built-in malware detection of Windows 10 became good enough so the antivirus ventors started adding "features" to make themselves stand out and look good on Enterprise comparison charts.
Thinking back on the Windows XP days... You'd be in actual danger if you didn't use one.
[1] https://arstechnica.com/information-technology/2017/05/windo...
https://cve.mitre.org/cgi-bin/cvekey.cgi?keyword=Eset
But from way back it's been RCE prone: https://support.eset.com/en/news325-eset-customer-advisory-v...
Agree that 90% of CVE's are meaningless but unless they've done a lot of sandboxing work in the meantime (guessing not, and up to them to show that) it's hard to trust.
Given the CVEs published, do you feel confident that if the product were robustly fuzzed / reversed+ tomorrow that there wouldn't be low hanging RCE? How safe do you feel running Windows with that product versus without? Personally I trust Microsoft's engineering / SDLC more than ESETs, maybe just me.
Symantec broke Chrome on multiple machines for me.
>The Google researchers found that MsMpEngine contains a component called NScript that analyses any filesystem or network activity that looks like JavaScript. NScript isn't sandboxed and runs at a very high privilege level, and it's used to evaluate untrusted code by default on almost every modern Windows system
Every antivirus is bad.
[1] https://arstechnica.com/information-technology/2017/05/windo...