cbcvebase.
CVE-2017-8541
published 2017-05-26

CVE-2017-8541: The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1…

PriorityP265high7.8CVSS 3.0
AVLACLPRNUIRSUCHIHAH
EXPLOIT
EPSS
50.28%
98.8th percentile
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016, Microsoft Exchange Server 2013 and 2016, does not properly scan a specially crafted file leading to memory corruption. aka "Microsoft Malware Protection Engine Remote Code Execution Vulnerability", a different vulnerability than CVE-2017-8538 and CVE-2017-8540.

Affected

15 ranges
VendorProductVersion rangeFixed in
microsoftexchange_server
microsoftexchange_server
microsoftforefront_endpoint_protection
microsoftmalware_protection_engine<= 1.1.13704.0
microsoftmalware_protection_engine>= 1.1.13701.0 < 1.1.13704.01.1.13704.0
microsoft_corporationmalware_protection_engine
msrcmicrosoft_endpoint_protection
msrcmicrosoft_exchange_server_2013
msrcmicrosoft_exchange_server_2016
msrcmicrosoft_forefront_endpoint_protection
msrcmicrosoft_forefront_endpoint_protection_2010
msrcmicrosoft_security_essentials
msrcmicrosoft_system_center_endpoint_protection
msrcwindows_defender
msrcwindows_intune_endpoint_protection

Detection & IOCsextracted from sources · hover to see the quote

urlhttps://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/42092.zip
filenamempengine.dll
version1.1.13701.0
  • The vulnerability is a Use-After-Free in JsRuntimeState::setCaller — the saved caller at offset 0x158 (rcx+158h in 64-bit) is not marked by the garbage collector, enabling UAF exploitation when mpengine.dll scans a crafted JS file.
  • Trigger path: a specially crafted file delivered via web, email, IM, or user-uploaded content is scanned by the Malware Protection Engine — monitor for mpengine.dll processing unexpected JS/script files, especially with real-time protection enabled.
  • Exploitation results in code execution as LocalSystem — alert on unexpected child processes or privilege escalation originating from the MsMpEng.exe process context.
  • Verify mpengine.dll version is 1.1.13704.0 or later; any system running version 1.1.13701.0 or earlier is vulnerable and should be flagged in asset inventory.
  • ·Windows Server 2008 R2 systems are NOT affected if the Desktop Experience feature is not installed — scope detection rules accordingly.
  • ·The PoC zip archive is password-protected; the password is 'calleruaf' — use this when analysing the sample in a controlled environment.
  • ·The UAF crash behaviour differs between platforms — the bug does not produce reliable crashes on Windows without chaining with a second bug (#1258), so crash-based detection alone may miss exploitation.

CVSS provenance

nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_msrc7.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.