cbcvebase.
CVE-2017-8538
published 2017-05-26

CVE-2017-8538: The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1…

PriorityP265high7.8CVSS 3.0
AVLACLPRNUIRSUCHIHAH
EXPLOIT
EPSS
50.28%
98.8th percentile
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016, Microsoft Exchange Server 2013 and 2016, does not properly scan a specially crafted file leading to memory corruption. aka "Microsoft Malware Protection Engine Remote Code Execution Vulnerability", a different vulnerability than CVE-2017-8540 and CVE-2017-8541.

Affected

15 ranges
VendorProductVersion rangeFixed in
microsoftexchange_server
microsoftexchange_server
microsoftforefront_endpoint_protection
microsoftmalware_protection_engine<= 1.1.13704.0
microsoftmalware_protection_engine>= 1.1.13701.0 < 1.1.13704.01.1.13704.0
microsoft_corporationmalware_protection_engine
msrcmicrosoft_endpoint_protection
msrcmicrosoft_exchange_server_2013
msrcmicrosoft_exchange_server_2016
msrcmicrosoft_forefront_endpoint_protection
msrcmicrosoft_forefront_endpoint_protection_2010
msrcmicrosoft_security_essentials
msrcmicrosoft_system_center_endpoint_protection
msrcwindows_defender
msrcwindows_intune_endpoint_protection

Detection & IOCsextracted from sources · hover to see the quote

urlhttps://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/42081.zip
filenamempengine.dll
version1.1.13701.0
version1.1.13704.0
  • Crash/memory corruption in mpengine.dll triggered by malformed file scan — monitor MsMpEng.exe for unhandled exceptions or unexpected termination, particularly in heap-related symbols.
  • Heap buffer overflow (one-byte) observable via PageHeap on MsMpEng.exe; crash symbol: free() called by NET_thread_ctx_t__FreeState_void_
  • Heap corruption observable via PageHeap on MsMpEng.exe; crash symbol: free() called by CRsaPublicKey__Decrypt_uchar — may also manifest as invalid read.
  • Unspecified memory corruption in netvm_parse_routine_netinvoke_handle_t; exhibits different crash behavior with and without PageHeap enabled.
  • Exploitation vector: attacker delivers specially crafted file via web, email, or instant messenger — file is auto-scanned by MsMpEng when real-time protection is enabled, requiring no user interaction beyond receiving/viewing.
  • Verify MsMpEng.exe engine version is 1.1.13704.0 or later; versions at or below 1.1.13701.0 are vulnerable.
  • Windows Server 2008 R2 systems without the Desktop Experience feature installed are not affected — use this as a scoping filter when triaging exposure.
  • ·PoC archive is password-protected; password is 'mpengbugs'.
  • ·Heap corruption bugs (corruption_1 and corruption_2) require PageHeap to be enabled on MsMpEng.exe to reliably observe the unhandled exception in a lab/detection context.
  • ·All crashes were verified on Windows 7 when an offending sample is saved to disk and discovered by MsMpEng; behavior on other platforms may differ.
  • ·The exploit status is publicly disclosed but not yet exploited in the wild at time of advisory; exploitation assessed as 'Less Likely' for both latest and older software releases.

CVSS provenance

nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_msrc7.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.