Executive brief
The Microsoft Malware Protection Engine fails to properly scan specially crafted files, leading to memory corruption. An attacker who successfully exploited this vulnerability could execute arbitrary code in the security context of the LocalSystem account.
Affected products
- Microsoft Malware Protection Engine up to 1.1.13704.0
- Microsoft Windows Defender
- Microsoft Forefront Security
- Microsoft Exchange Server 2013
- Microsoft Exchange Server 2016
- Microsoft Windows 10
- Microsoft Windows 7 SP1
- Microsoft Windows 8.1
- Microsoft Windows Server 2008 SP2 / R2 SP1
- Microsoft Windows Server 2012 / R2
- Microsoft Windows Server 2016
Timeline
- 2017-05-25: other: Exploit published on Exploit-DB
- 2022-03-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2022-03-03: disclosed