CVE-2017-0290
published 2017-05-09CVE-2017-0290: The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1…
PriorityP270high7.8CVSS 3.0
AVLACLPRNUIRSUCHIHAH
EXPLOIT
EPSS
77.21%
99.5th percentile
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 does not properly scan a specially crafted file leading to memory corruption, aka "Microsoft Malware Protection Engine Remote Code Execution Vulnerability."
Affected
20 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | malware_protection_engine | <= 1.1.13701.0 | — |
| microsoft_corporation | microsoft_malware_protection_engine | — | — |
| msrc | microsoft_forefront_endpoint_protection_2010 | — | — |
| msrc | microsoft_forefront_security_for_sharepoint_service_pack_3 | — | — |
| msrc | microsoft_security_essentials | — | — |
| msrc | windows_defender_on_windows_10_for_32-bit_systems | — | — |
| msrc | windows_defender_on_windows_10_for_x64-based_systems | — | — |
| msrc | windows_defender_on_windows_10_version_1511_for_32-bit_systems | — | — |
| msrc | windows_defender_on_windows_10_version_1511_for_x64-based_systems | — | — |
| msrc | windows_defender_on_windows_10_version_1607_for_32-bit_systems | — | — |
| msrc | windows_defender_on_windows_10_version_1607_for_x64-based_systems | — | — |
| msrc | windows_defender_on_windows_10_version_1703_for_32-bit_systems | — | — |
| msrc | windows_defender_on_windows_10_version_1703_for_x64-based_systems | — | — |
| msrc | windows_defender_on_windows_7_for_32-bit_systems_service_pack_1 | — | — |
| msrc | windows_defender_on_windows_7_for_x64-based_systems_service_pack_1 | — | — |
| msrc | windows_defender_on_windows_8.1_for_32-bit_systems | — | — |
| msrc | windows_defender_on_windows_8.1_for_x64-based_systems | — | — |
| msrc | windows_defender_on_windows_rt_8.1 | — | — |
| msrc | windows_defender_on_windows_server_2016 | — | — |
| msrc | windows_intune_endpoint_protection | — | — |
Detection & IOCsextracted from sources · hover to see the quote
pathc:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{1C2B7358-645B-41D0-9E79-5FA3E5C4EB51}\mpengine.dll↗
- →The vulnerability is triggered by any file written to disk (downloads, email attachments, browser cache, temp files) — MIME type and file extension are irrelevant; MsMpEng uses its own content identification system, so network-level filtering by file type is ineffective. ↗
- →Exploit delivery vectors include email (no user interaction required — reading or opening is not necessary), web browsing, instant messaging, and any mechanism that writes attacker-controlled content to disk. ↗
- →MsMpEng runs as NT AUTHORITY\SYSTEM (S-1-5-18) without sandboxing; successful exploitation results in SYSTEM-level code execution — alert on unexpected child processes or network connections spawned from MsMpEng.exe. ↗
- →The exploit abuses NScript (mpengine's unsandboxed JavaScript interpreter) via a type confusion in JsDelegateObject_Error::toString() — the 'message' property of an Error object is not type-validated before being passed to JsRuntimeState::triggerShortStrEvent(), allowing an integer handle to be treated as a vtable pointer. ↗
- →Deeply nested or obscure archive formats (e.g., Amiga ZOO, MagicISO UIF) can be used to deliver the payload — mpengine unpacks arbitrarily deeply nested archives, making network-level identification impractical. ↗
- →Verify mpengine.dll version on all endpoints; any version at or below 1.1.13701.0 is vulnerable. Detection query: check engine version reported by antimalware software against the patched threshold of 1.1.13704.0. ↗
- ·On Windows 10, adding a blanket exception for C:\ prevents automatic filesystem scanning by MsMpEng, which would block exploitation — however this also disables real-time protection entirely and is not a recommended mitigation. ↗
- ·MsMpEng uses a filesystem minifilter to intercept ALL system filesystem activity — any write to disk (including browser caches, temp files, unconfirmed downloads) is sufficient to trigger scanning and thus exploitation, regardless of where the file lands. ↗
- ·Server-side exposure is significant: Exchange and IIS deployments running affected engine versions are remotely exploitable without authentication, as MsMpEng scans inbound content on those services. ↗
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_msrc7.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Microsoft Malware Protection Engine Remote Code Execution Vulnerability
vendor_msrc·2017-05-09·CVSS 7.8
CVE-2017-0290 [HIGH] Microsoft Malware Protection Engine Remote Code Execution Vulnerability
Microsoft Malware Protection Engine Remote Code Execution Vulnerability
Description: A remote code execution vulnerability exists when the Microsoft Malware Protection Engine does not properly scan a specially crafted file, leading to memory corruption. An attacker who successfully exploited this vulnerability could execute arbitrary code in the security context of the LocalSystem account and take control of the system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
To exploit this vulnerability, a specially crafted file must be scanned by an affected version of the Microsoft Malware Protection Engine. There are many ways that an attacker could place a specially crafted file in a location that is scanned by the Microsof
GHSA
GHSA-w3hq-vf6w-p52j: The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows
ghsa_unreviewed·2022-05-14
CVE-2017-0290 [HIGH] CWE-119 GHSA-w3hq-vf6w-p52j: The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 does not properly scan a specially crafted file leading to memory corruption, aka "Microsoft Malware Protection Engine Remote Code Execution Vulnerability."
No detection rules found.
Bleepingcomputer
NoName ransomware gang deploying RansomHub malware in recent attacks
blogs_bleepingcomputer·2024-09-10·CVSS 8.8
[HIGH] NoName ransomware gang deploying RansomHub malware in recent attacks
## NoName ransomware gang deploying RansomHub malware in recent attacks
## Bill Toulas
The NoName ransomware gang has been trying to build a reputation for more than three years targeting small and medium-sized businesses worldwide with its encryptors and may now be working as a RansomHub affiliate.
The gang uses custom tools known as the Spacecolon malware family, and deploys them after gaining access to a network through brute-force methods as well as exploiting older vulnerabilities like EternalBlue (CVE-2017-0144) or ZeroLogon (CVE-2020-1472).
In more recent attacks NoName uses the ScRansom ransomware, which replaced the Scarab encryptor. Additionally, the threat actor tried to make a name by experimenting with the leaked LockBit 3.0 ransomware builder, creating a similar data leak
Talos
Microsoft Patch Tuesday - May 2017
blogs_talos·2017-05-10·CVSS 7.5
CVE-2017-0290 [HIGH] Microsoft Patch Tuesday - May 2017
Today, Microsoft has release their monthly set of security updates designed to address vulnerabilities. This month's release addresses 56 vulnerabilities with 15 of them rated critical and 41 rated important. Impacted products include .NET, DirectX, Edge, Internet Explorer, Office, Sharepoint, and Windows.
In addition to the coverage Talos is providing for the normal monthly Microsoft security advisories, Talos is also providing coverage for CVE-2017-0290, the MsMpEng Malware Protection service vulnerability in Windows reported by Natalie Silvanovich and Tavis Ormandy of Google Project Zero. Snort rule SIDs for this specific vulnerability are 42820-42821.
## Vulnerabilities Rated Critical The following vulnerabilities are rated critical by Microsoft:
- CVE-2017-0221
- CVE-2017-0222
- CV
Talos
Microsoft Patch Tuesday - May 2017
blogs_talos·2017-05-10·CVSS 7.5
CVE-2017-0290 [HIGH] Microsoft Patch Tuesday - May 2017
## Microsoft Patch Tuesday - May 2017
Today, Microsoft has release their monthly set of security updates designed to address vulnerabilities. This month's release addresses 56 vulnerabilities with 15 of them rated critical and 41 rated important. Impacted products include .NET, DirectX, Edge, Internet Explorer, Office, Sharepoint, and Windows.
In addition to the coverage Talos is providing for the normal monthly Microsoft security advisories, Talos is also providing coverage for CVE-2017-0290, the MsMpEng Malware Protection service vulnerability in Windows reported by Natalie Silvanovich and Tavis Ormandy of Google Project Zero. Snort rule SIDs for this specific vulnerability are 42820-42821.
## Vulnerabilities Rated Critical The following vulnerabilities are rated critical by Microsoft
Qualys
Microsoft Fixes Malware Protection Engine and Several 0-Day Vulnerabilities, and Deprecates SHA-1 | Qualys
blogs_qualys·2017-05-09·CVSS 8.8
[HIGH] Microsoft Fixes Malware Protection Engine and Several 0-Day Vulnerabilities, and Deprecates SHA-1 | Qualys
Hours before today’s Patch Tuesday release on the eve of May 8, Microsoft released an emergency updated to fix a vulnerability in their Malware Protection Engine. This critical vulnerability allows an attacker to take complete control of the victim’s machine by just sending an e-mail attachment. When the malware protection engine scans the attachment the malicious code in the file gets executed, allowing the attacker complete and full access to the computer. The attack can also be carried out by sending the file via an instant message or having the victim download the file from a website. It is absolutely essential that organizations using Microsoft Malware Protection Engine make sure that they are at version Version 1.1.13704.0 or later. Users should also check if they are patched for CVE
Qualys
Microsoft Fixes Malware Protection Engine and Several 0-Day Vulnerabilities, and Deprecates SHA-1
blogs_qualys·2017-05-09·CVSS 8.8
[HIGH] Microsoft Fixes Malware Protection Engine and Several 0-Day Vulnerabilities, and Deprecates SHA-1
Hours before today’s Patch Tuesday release on the eve of May 8, Microsoft released an emergency updated to fix a vulnerability in their Malware Protection Engine. This critical vulnerability allows an attacker to take complete control of the victim’s machine by just sending an e-mail attachment. When the malware protection engine scans the attachment the malicious code in the file gets executed, allowing the attacker complete and full access to the computer. The attack can also be carried out by sending the file via an instant message or having the victim download the file from a website. It is absolutely essential that organizations using Microsoft Malware Protection Engine make sure that they are at version Version 1.1.13704.0 or later. Users should also check if they are patched for CVE
http://www.securityfocus.com/bid/98330http://www.securitytracker.com/id/1038419http://www.securitytracker.com/id/1038420https://0patch.blogspot.si/2017/05/0patching-worst-windows-remote-code.htmlhttps://arstechnica.com/information-technology/2017/05/windows-defender-nscript-remote-vulnerability/https://bugs.chromium.org/p/project-zero/issues/detail?id=1252https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0290https://technet.microsoft.com/library/security/4022344https://twitter.com/natashenka/status/861748397409058816https://www.exploit-db.com/exploits/41975/http://www.securityfocus.com/bid/98330http://www.securitytracker.com/id/1038419http://www.securitytracker.com/id/1038420https://0patch.blogspot.si/2017/05/0patching-worst-windows-remote-code.htmlhttps://arstechnica.com/information-technology/2017/05/windows-defender-nscript-remote-vulnerability/https://bugs.chromium.org/p/project-zero/issues/detail?id=1252https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0290https://technet.microsoft.com/library/security/4022344https://twitter.com/natashenka/status/861748397409058816https://www.exploit-db.com/exploits/41975/
2017-05-09
Published