cbcvebase.
CVE-2017-8558
published 2017-06-29

CVE-2017-8558: The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on 32-bit versions of Microsoft Windows Server 2008 SP2 and R2…

high7.8CVSS 3.0
AVLACLPRLUINSUCHIHAH
EXPLOIT
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on 32-bit versions of Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703 does not properly scan a specially crafted file leading to memory corruption. aka "Microsoft Malware Protection Engine Remote Code Execution Vulnerability".

Affected

14 ranges
VendorProductVersion rangeFixed in
microsoftforefront_endpoint_protection
microsoft_corporationmicrosoft_malware_protection_engine
msrcmicrosoft_endpoint_protection
msrcmicrosoft_forefront_endpoint_protection
msrcmicrosoft_forefront_endpoint_protection_2010
msrcmicrosoft_security_essentials
msrcwindows_defender_on_windows_10_for_32-bit_systems
msrcwindows_defender_on_windows_10_version_1511_for_32-bit_systems
msrcwindows_defender_on_windows_10_version_1607_for_32-bit_systems
msrcwindows_defender_on_windows_10_version_1703_for_32-bit_systems
msrcwindows_defender_on_windows_7_for_32-bit_systems_service_pack_1
msrcwindows_defender_on_windows_8.1_for_32-bit_systems
msrcwindows_defender_on_windows_server_2008_for_32-bit_systems_service_pack_2
msrcwindows_intune_endpoint_protection