cbcvebase.
CVE-2021-42298
published 2021-11-10

CVE-2021-42298: Microsoft Defender Remote Code Execution Vulnerability

PriorityP277high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
ITWVulnCheck KEV
Exploited in the wild
EPSS
5.29%
91.7th percentile
Microsoft Defender Remote Code Execution Vulnerability

Affected

3 ranges
VendorProductVersion rangeFixed in
microsoftmalware_protection_engine< 1.1.18700.31.1.18700.3
microsoftmicrosoft_malware_protection_engine>= 1.1.0.0 < 1.1.18700.31.1.18700.3
msrcmicrosoft_malware_protection_engine

Detection & IOCsextracted from sources · hover to see the quote

version1.1.18700.3
filenamempengine.dll
snort
58519
snort
58520
snort
58539
snort
58540
snort
58541
snort
300054
  • Check Microsoft Malware Protection Engine version on endpoints; any version below 1.1.18700.3 is vulnerable. Systems with Defender disabled are NOT in an exploitable state despite binaries remaining on disk.
  • Vulnerability scanners may false-positive on disabled Defender installs; confirm exploitability only when Defender is active.
  • CVE-2021-42298 is reportedly exploited by the 'Varison' threat group; threat-hunt for this group's TTPs on Windows endpoints running unpatched Defender.
  • ·Affected component is Microsoft Malware Protection Engine (mpengine.dll); all products using this engine are affected, including Microsoft Defender, System Center Endpoint Protection, and Microsoft Security Essentials.
  • ·The patch is delivered automatically via antimalware definition/engine update channels; no manual OS patch is required, but enterprise admins must confirm auto-update pipelines are functioning.

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vulncheck7.8HIGH
vendor_msrc7.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.