Junglewise Threat Intelligence

CVE-2017-8540: Microsoft Malware Protection Engine Improper Restriction of Operations Vulnerability

CVE-2017-8540 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2022-03-03

Technologies: Microsoft Exchange Server 2016, Microsoft Windows Server 2012 R2, Microsoft Malware Protection Engine, Microsoft Windows 8.1, Microsoft Windows 10, Microsoft Windows Server 2016. Vendors: Microsoft.

Executive brief

The Microsoft Malware Protection Engine fails to properly scan specially crafted files, leading to memory corruption. An attacker who successfully exploited this vulnerability could execute arbitrary code in the security context of the LocalSystem account.

Affected products

  • Microsoft Malware Protection Engine up to 1.1.13704.0
  • Microsoft Windows Defender
  • Microsoft Forefront Security
  • Microsoft Exchange Server 2013
  • Microsoft Exchange Server 2016
  • Microsoft Windows 10
  • Microsoft Windows 7 SP1
  • Microsoft Windows 8.1
  • Microsoft Windows Server 2008 SP2 / R2 SP1
  • Microsoft Windows Server 2012 / R2
  • Microsoft Windows Server 2016

Timeline

  • 2017-05-25: other: Exploit published on Exploit-DB
  • 2022-03-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-03-03: disclosed

Related threats