Home / Vulnerabilities / CVE-2017-8540
HIGH SEVERITY
CVE-2017-8540 Microsoft · Malware Protection Engine

Microsoft Malware Protection Engine Improper Restriction of Operations Vulnerability

Technical Severity

CVSS v3.1 Metrics

HIGH
7.8 / 10
Minimal Risk Critical
Vector Specification
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitation Likelihood

EPSS Prediction

84.61 %
Predictive Probability
Percentile Rank
99.3 th

Documented as more likely to be exploited than 99.3% of known CVEs.

Detection Date

Mar 03, 2022

Remediation Due

Mar 24, 2022

CISA Catalog Active

Threat Analysis

The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016, Microsoft Exchange Server 2013 and 2016, does not properly scan a specially crafted file leading to memory corruption. aka "Microsoft Malware Protection Engine Remote Code Execution Vulnerability".

Remediation Directive

Apply updates per vendor instructions.

External Intelligence