Remote Code Execution Vulnerability in Microsoft Malware Protection Engine on Multiple Windows Platforms
CVE-2017-8541
Summary
The Microsoft Malware Protection Engine, utilized in various versions of Microsoft Windows and Exchange Server, suffers from a vulnerability that allows for remote code execution due to improper scanning of specially crafted files. This flaw can lead to memory corruption and could allow an attacker to execute arbitrary code on affected systems, potentially compromising the integrity and security of user data.
Affected Version(s)
Malware Protection Engine Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016
References
EPSS Score
73% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved