9.3

CVE-2017-8540

Warnung
Exploit
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016, Microsoft Exchange Server 2013 and 2016, does not properly scan a specially crafted file leading to memory corruption. aka "Microsoft Malware Protection Engine Remote Code Execution Vulnerability", a different vulnerability than CVE-2017-8538 and CVE-2017-8541.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Malware Protection Engine Version >= 1.1.13701.0 < 1.1.13704.0
   Microsoft ≫ Windows 10 1507 Version -
   Microsoft ≫ Windows 10 1511 Version -
   Microsoft ≫ Windows 10 1607 Version -
   Microsoft ≫ Windows 10 1703 Version -
   Microsoft ≫ Windows 7 Version - Update sp1
   Microsoft ≫ Windows 8.1 Version -
   Microsoft ≫ Windows Rt 8.1 Version -
   Microsoft ≫ Windows Server 2008 Version - Update sp2
   Microsoft ≫ Windows Server 2008 Version r2 Update sp1
   Microsoft ≫ Windows Server 2012 Version -
   Microsoft ≫ Windows Server 2012 Version r2
   Microsoft ≫ Windows Server 2016 Version -
Microsoft ≫ Exchange Server Version 2013 Update -
Microsoft ≫ Exchange Server Version 2016 Update -
Microsoft ≫ Windows Defender Version -

03.03.2022: CISA Known Exploited Vulnerabilities (KEV) Catalog

Microsoft Malware Protection Engine Improper Restriction of Operations Vulnerability

Schwachstelle

The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016, Microsoft Exchange Server 2013 and 2016, does not properly scan a specially crafted file leading to memory corruption. aka "Microsoft Malware Protection Engine Remote Code Execution Vulnerability".

Beschreibung

Apply updates per vendor instructions.

Erforderliche Maßnahmen
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 71.96% 0.994
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
NIST 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C
CISA-ADP 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CWE-787 Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

http://www.securitytracker.com/id/1038571
Third Party Advisory
Broken Link
VDB Entry
http://www.securityfocus.com/bid/98703
Third Party Advisory
Broken Link
VDB Entry
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-8540
Patch
Vendor Advisory
Mitigation
https://www.exploit-db.com/exploits/42088/
Third Party Advisory
Exploit
VDB Entry
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-8540
US Government Resource