9.3

CVE-2017-8558

The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on 32-bit versions of Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703 does not properly scan a specially crafted file leading to memory corruption. aka "Microsoft Malware Protection Engine Remote Code Execution Vulnerability".
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Windows Defender Version -
   Microsoft ≫ Windows 10 Version - HwPlatform x86
   Microsoft ≫ Windows 10 Version 1511 HwPlatform x86
   Microsoft ≫ Windows 10 Version 1607 HwPlatform x86
   Microsoft ≫ Windows 10 Version 1703 HwPlatform x86
   Microsoft ≫ Windows 7 Version - Update sp1 HwPlatform x86
   Microsoft ≫ Windows 8.1 Version - HwPlatform x86
   Microsoft ≫ Windows Server 2008 Version - Update sp2 HwPlatform x86
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 43.59% 0.986
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.8 1.8 5.9
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
NIST 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

http://www.securityfocus.com/bid/99262
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1038783
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1038784
Third Party Advisory
VDB Entry
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-8558
Vendor Advisory
https://www.exploit-db.com/exploits/42264/
Third Party Advisory
VDB Entry