← All CVEs

CVE-2017-8540

high · 7.8Actively exploited

On the CISA Known Exploited Vulnerabilities catalog

Apply updates per vendor instructions.

Added 2022-03-03Remediation due 2022-03-24

The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016, Microsoft Exchange Server 2013 and 2016, does not properly scan a specially crafted file leading to memory corruption. aka "Microsoft Malware Protection Engine Remote Code Execution Vulnerability", a different vulnerability than CVE-2017-8538 and CVE-2017-8541.

7.8
CVSS
71.9%
EPSS (exploit prob.)
99th
EPSS percentile
2017-05-26
Published

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Weaknesses

CWE-787

Affected products

VendorProductAffected versions
microsoftmalware_protection_engine>= 1.1.13701.0, < 1.1.13704.0
microsoftwindows_10_1507all versions
microsoftwindows_10_1511all versions
microsoftwindows_10_1607all versions
microsoftwindows_10_1703all versions
microsoftwindows_7all versions
microsoftwindows_8.1all versions
microsoftwindows_rt_8.1all versions
microsoftwindows_server_2008all versions
microsoftwindows_server_2008r2
microsoftwindows_server_2012all versions
microsoftwindows_server_2012r2
microsoftwindows_server_2016all versions
microsoftendpoint_protectionall versions
microsoftexchange_server2013
microsoftexchange_server2016
microsoftforefront_endpoint_protectionall versions
microsoftforefront_endpoint_protection2010
microsoftforefront_securityall versions
microsoftintune_endpoint_protectionall versions
microsoftsecurity_essentialsall versions
microsoftsystem_center_endpoint_protectionall versions
microsoftwindows_defenderall versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2017-8540