CVE-2017-8540: Microsoft Malware Protection Engine Improper Restriction of Operations Vulnerability
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016, Microsoft Exchange Server 2013 and 2016, does not properly scan a specially crafted file leading to memory corruption. aka "Microsoft Malware Protection Engine Remote Code Execution Vulnerability". Required action: Apply updates per vendor instructions.
· high severity · unattributed attribution
Evidence and provenance
- Original source
- CISA KEV report ↗
- Published
- 2022-03-03T00:00:00Z
- Confidence basis
- No actor match
- Record ID
bac7747ccf6201051fb3
Vulnerabilities
CVE-2017-8540
Use and citation
Verify the original report before making operational decisions. Cite this permanent page together with the original source, publication date, confidence level, and review status.