CVE-2017-8541
published 2017-05-26CVE-2017-8541: The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1…
PriorityP265high7.8CVSS 3.0
AVLACLPRNUIRSUCHIHAH
EXPLOIT
EPSS
50.28%
98.8th percentile
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016, Microsoft Exchange Server 2013 and 2016, does not properly scan a specially crafted file leading to memory corruption. aka "Microsoft Malware Protection Engine Remote Code Execution Vulnerability", a different vulnerability than CVE-2017-8538 and CVE-2017-8540.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | exchange_server | — | — |
| microsoft | exchange_server | — | — |
| microsoft | forefront_endpoint_protection | — | — |
| microsoft | malware_protection_engine | <= 1.1.13704.0 | — |
| microsoft | malware_protection_engine | >= 1.1.13701.0 < 1.1.13704.0 | 1.1.13704.0 |
| microsoft_corporation | malware_protection_engine | — | — |
| msrc | microsoft_endpoint_protection | — | — |
| msrc | microsoft_exchange_server_2013 | — | — |
| msrc | microsoft_exchange_server_2016 | — | — |
| msrc | microsoft_forefront_endpoint_protection | — | — |
| msrc | microsoft_forefront_endpoint_protection_2010 | — | — |
| msrc | microsoft_security_essentials | — | — |
| msrc | microsoft_system_center_endpoint_protection | — | — |
| msrc | windows_defender | — | — |
| msrc | windows_intune_endpoint_protection | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →The vulnerability is a Use-After-Free in JsRuntimeState::setCaller — the saved caller at offset 0x158 (rcx+158h in 64-bit) is not marked by the garbage collector, enabling UAF exploitation when mpengine.dll scans a crafted JS file. ↗
- →Trigger path: a specially crafted file delivered via web, email, IM, or user-uploaded content is scanned by the Malware Protection Engine — monitor for mpengine.dll processing unexpected JS/script files, especially with real-time protection enabled. ↗
- →Exploitation results in code execution as LocalSystem — alert on unexpected child processes or privilege escalation originating from the MsMpEng.exe process context. ↗
- →Verify mpengine.dll version is 1.1.13704.0 or later; any system running version 1.1.13701.0 or earlier is vulnerable and should be flagged in asset inventory. ↗
- ·Windows Server 2008 R2 systems are NOT affected if the Desktop Experience feature is not installed — scope detection rules accordingly. ↗
- ·The PoC zip archive is password-protected; the password is 'calleruaf' — use this when analysing the sample in a controlled environment. ↗
- ·The UAF crash behaviour differs between platforms — the bug does not produce reliable crashes on Windows without chaining with a second bug (#1258), so crash-based detection alone may miss exploitation. ↗
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_msrc7.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Microsoft Malware Protection Engine Remote Code Execution Vulnerability
vendor_msrc·2017-05-09·CVSS 7.8
CVE-2017-8541 [HIGH] Microsoft Malware Protection Engine Remote Code Execution Vulnerability
Microsoft Malware Protection Engine Remote Code Execution Vulnerability
Description: A remote code execution vulnerability exists when the Microsoft Malware Protection Engine does not properly scan a specially crafted file, leading to memory corruption. An attacker who successfully exploited this vulnerability could execute arbitrary code in the security context of the LocalSystem account and take control of the system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
To exploit this vulnerability, a specially crafted file must be scanned by an affected version of the Microsoft Malware Protection Engine. There are many ways that an attacker could place a specially crafted file in a location that is scanned by the Microsof
GHSA
GHSA-vmvp-q95h-cjxj: The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows
ghsa_unreviewed·2022-05-17·CVSS 7.8
CVE-2017-8541 [HIGH] CWE-119 GHSA-vmvp-q95h-cjxj: The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016, Microsoft Exchange Server 2013 and 2016, does not properly scan a specially crafted file leading to memory corruption. aka "Microsoft Malware Protection Engine Remote Code Execution Vulnerability", a different vulnerability than CVE-2017-8538 and CVE-2017-8540.
GHSA
GHSA-342q-x494-83vw: The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows
ghsa_unreviewed·2022-05-17·CVSS 7.8
CVE-2017-8540 [HIGH] CWE-119 GHSA-342q-x494-83vw: The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016, Microsoft Exchange Server 2013 and 2016, does not properly scan a specially crafted file leading to memory corruption. aka "Microsoft Malware Protection Engine Remote Code Execution Vulnerability", a different vulnerability than CVE-2017-8538 and CVE-2017-8541.
GHSA
GHSA-vppm-w8jw-cghw: The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows
ghsa_unreviewed·2022-05-17·CVSS 7.8
CVE-2017-8538 [HIGH] CWE-119 GHSA-vppm-w8jw-cghw: The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016, Microsoft Exchange Server 2013 and 2016, does not properly scan a specially crafted file leading to memory corruption. aka "Microsoft Malware Protection Engine Remote Code Execution Vulnerability", a different vulnerability than CVE-2017-8540 and CVE-2017-8541.
No detection rules found.
No writeups or analysis indexed.
http://www.securityfocus.com/bid/98710http://www.securitytracker.com/id/1038571https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-8541https://www.exploit-db.com/exploits/42092/http://www.securityfocus.com/bid/98710http://www.securitytracker.com/id/1038571https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-8541https://www.exploit-db.com/exploits/42092/
2017-05-26
Published