cbcvebase.
CVE-2018-0986
published 2018-04-04

CVE-2018-0986: A remote code execution vulnerability exists when the Microsoft Malware Protection Engine does not properly scan a specially crafted file, leading to memory…

PriorityP188high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
ITWEXPLOITVulnCheck KEVRansomware
Exploited in the wild
EPSS
61.48%
99.1th percentile
A remote code execution vulnerability exists when the Microsoft Malware Protection Engine does not properly scan a specially crafted file, leading to memory corruption, aka "Microsoft Malware Protection Engine Remote Code Execution Vulnerability." This affects Windows Defender, Windows Intune Endpoint Protection, Microsoft Security Essentials, Microsoft System Center Endpoint Protection, Microsoft Exchange Server, Microsoft System Center, Microsoft Forefront Endpoint Protection.

Affected

67 ranges· showing 25
VendorProductVersion rangeFixed in
microsoftexchange_server
microsoftexchange_server
microsoftmicrosoft_exchange_server
microsoftmicrosoft_exchange_server
microsoftmicrosoft_forefront_endpoint_protection
microsoftmicrosoft_security_essentials
microsoftmicrosoft_system_center
microsoftmicrosoft_system_center
microsoftmicrosoft_system_center_endpoint_protection
microsoftsystem_center_endpoint_protection
microsoftwindows_defender
microsoftwindows_defender
microsoftwindows_defender
microsoftwindows_defender
microsoftwindows_defender
microsoftwindows_defender
microsoftwindows_defender
microsoftwindows_defender
microsoftwindows_defender
microsoftwindows_defender
microsoftwindows_defender
microsoftwindows_defender
microsoftwindows_defender
microsoftwindows_defender
microsoftwindows_defender

Detection & IOCsextracted from sources · hover to see the quote

filenamempengine.dll
urlhttps://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/44402.zip
versionmpengine.dll < 1.1.14700.5
  • Trigger condition: a specially crafted RAR file processed by mpengine.dll's VMSF_RGB filter with PosR=-2 and DataSize=1 causes an out-of-bounds write (memory corruption/crash). Monitor Windows Defender scan crashes or mpengine.dll faults as a detection signal.
  • The vulnerable code path is in RarVM::ExecuteStandardFilter, specifically the VMSF_RGB case within mpengine.dll's RAR archive processing. Detections should focus on malformed RAR files triggering this filter.
  • Exploitation requires no user interaction when Windows Defender real-time protection is enabled — any file delivered via email, IM, web download, or shared upload that is scanned by MMPE can trigger the vulnerability automatically.
  • Verify mpengine.dll version on endpoints; any version at or below 1.1.14600.4 is vulnerable. Use Nessus Plugin ID 108813 to identify unpatched systems.
  • The exploit abuses the VMSF_UPCASE filter path still present in mpengine.dll's forked unrar code (derived from unrar ≤ 4.2.4), which was removed in unrar 5.0. Presence of VMSF_RGB/VMSF_UPCASE processing in RAR VM execution is the attack surface.
  • ·Exploitation is fully automatic (zero-click) only when Windows Defender real-time protection is enabled. If real-time scanning is disabled, exploitation is deferred until a scheduled scan runs.
  • ·Successful exploitation grants code execution as LocalSystem, the highest local privilege level, not just the user context.

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vulncheck8.8HIGH
vendor_msrc9.1CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.