CVE-2017-8540
published 2017-05-26CVE-2017-8540: The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1…
PriorityP187high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2022-03-24
Exploited in the wild
EPSS
71.96%
99.4th percentile
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016, Microsoft Exchange Server 2013 and 2016, does not properly scan a specially crafted file leading to memory corruption. aka "Microsoft Malware Protection Engine Remote Code Execution Vulnerability", a different vulnerability than CVE-2017-8538 and CVE-2017-8541.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | exchange_server | — | — |
| microsoft | exchange_server | — | — |
| microsoft | forefront_endpoint_protection | — | — |
| microsoft | malware_protection_engine | <= 1.1.13704.0 | — |
| microsoft | malware_protection_engine | >= 1.1.13701.0 < 1.1.13704.0 | 1.1.13704.0 |
| microsoft_corporation | malware_protection_engine | — | — |
| msrc | microsoft_endpoint_protection | — | — |
| msrc | microsoft_exchange_server_2013 | — | — |
| msrc | microsoft_exchange_server_2016 | — | — |
| msrc | microsoft_forefront_endpoint_protection | — | — |
| msrc | microsoft_forefront_endpoint_protection_2010 | — | — |
| msrc | microsoft_security_essentials | — | — |
| msrc | microsoft_system_center_endpoint_protection | — | — |
| msrc | windows_defender | — | — |
| msrc | windows_intune_endpoint_protection | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Trigger condition: a specially crafted file delivered via web, email, IM, or user-uploaded content is scanned by an affected version of mpengine.dll (≤ 1.1.13701.0); no user interaction beyond delivery is required when real-time protection is enabled. ↗
- →The exploit PoC zip is password-protected with the password 'nscriptgc'; detection of this specific password on archive files submitted to or scanned by Defender/MsMpEng is a strong indicator of exploit delivery. ↗
- →Exploitation results in code execution as LocalSystem; monitor for unexpected child processes or privilege escalation originating from MsMpEng.exe (the Malware Protection Engine host process). ↗
- →Verify mpengine.dll version on all endpoints; any version at or below 1.1.13701.0 is vulnerable. The patched version is 1.1.13704.0 or later. ↗
- ·Windows Server 2008 R2 systems are NOT affected if the Desktop Experience feature is not installed — scope detection rules accordingly. ↗
- ·The GC-disable flag (blockGC) passed to JsTree::run is frame-local, not global; a nested eval() in a valueOf/toString callback can bypass it and trigger a global GC, meaning detection logic must account for nested JsTree execution contexts. ↗
- ·The inline string optimisation in MsMpEng's JS engine means toString must return a string of more than three characters to avoid the optimisation path and reach the vulnerable code; PoC strings shorter than 4 chars will not trigger the UAF. ↗
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vulncheck7.8HIGH
cisa7.8HIGH
vendor_msrc7.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-vmvp-q95h-cjxj: The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows
ghsa_unreviewed·2022-05-17·CVSS 7.8
CVE-2017-8541 [HIGH] CWE-119 GHSA-vmvp-q95h-cjxj: The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016, Microsoft Exchange Server 2013 and 2016, does not properly scan a specially crafted file leading to memory corruption. aka "Microsoft Malware Protection Engine Remote Code Execution Vulnerability", a different vulnerability than CVE-2017-8538 and CVE-2017-8540.
GHSA
GHSA-342q-x494-83vw: The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows
ghsa_unreviewed·2022-05-17·CVSS 7.8
CVE-2017-8540 [HIGH] CWE-119 GHSA-342q-x494-83vw: The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016, Microsoft Exchange Server 2013 and 2016, does not properly scan a specially crafted file leading to memory corruption. aka "Microsoft Malware Protection Engine Remote Code Execution Vulnerability", a different vulnerability than CVE-2017-8538 and CVE-2017-8541.
GHSA
GHSA-vppm-w8jw-cghw: The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows
ghsa_unreviewed·2022-05-17·CVSS 7.8
CVE-2017-8538 [HIGH] CWE-119 GHSA-vppm-w8jw-cghw: The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016, Microsoft Exchange Server 2013 and 2016, does not properly scan a specially crafted file leading to memory corruption. aka "Microsoft Malware Protection Engine Remote Code Execution Vulnerability", a different vulnerability than CVE-2017-8540 and CVE-2017-8541.
VulnCheck
Microsoft Malware Protection Engine Improper Restriction of Operations Vulnerability
vulncheck·2017·CVSS 7.8
CVE-2017-8540 [HIGH] CWE-119 Microsoft Malware Protection Engine Improper Restriction of Operations Vulnerability
Microsoft Malware Protection Engine Improper Restriction of Operations Vulnerability
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016, Microsoft Exchange Server 2013 and 2016, does not properly scan a specially crafted file leading to memory corruption. aka "Microsoft Malware Protection Engine Remote Code Execution Vulnerability".
Affected: Microsoft Malware Protection Engine
Required Action: Apply updates per vendor instructions.
Exploitation References: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
Remediation Due:
CISA
Microsoft Malware Protection Engine Improper Restriction of Operations Vulnerability
cisa·2022-03-03·CVSS 7.8
CVE-2017-8540 [HIGH] CWE-119 Microsoft Malware Protection Engine Improper Restriction of Operations Vulnerability
Vulnerability: Microsoft Malware Protection Engine Improper Restriction of Operations Vulnerability
Affected: Microsoft Malware Protection Engine
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016, Microsoft Exchange Server 2013 and 2016, does not properly scan a specially crafted file leading to memory corruption. aka "Microsoft Malware Protection Engine Remote Code Execution Vulnerability".
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2017-8540
Remediation Due Date: 2022-03-24
Microsoft
Microsoft Malware Protection Engine Remote Code Execution Vulnerability
vendor_msrc·2017-05-09·CVSS 7.8
CVE-2017-8540 [HIGH] Microsoft Malware Protection Engine Remote Code Execution Vulnerability
Microsoft Malware Protection Engine Remote Code Execution Vulnerability
Description: A remote code execution vulnerability exists when the Microsoft Malware Protection Engine does not properly scan a specially crafted file, leading to memory corruption. An attacker who successfully exploited this vulnerability could execute arbitrary code in the security context of the LocalSystem account and take control of the system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
To exploit this vulnerability, a specially crafted file must be scanned by an affected version of the Microsoft Malware Protection Engine. There are many ways that an attacker could place a specially crafted file in a location that is scanned by the Microsof
No detection rules found.
No writeups or analysis indexed.
http://www.securityfocus.com/bid/98703http://www.securitytracker.com/id/1038571https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-8540https://www.exploit-db.com/exploits/42088/http://www.securityfocus.com/bid/98703http://www.securitytracker.com/id/1038571https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-8540https://www.exploit-db.com/exploits/42088/https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-8540
2017-05-26
Published
2022-03-03
Added to CISA KEV
Exploited in the wild