CVE-2017-0290
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 does not properly scan a specially crafted file leading to memory corruption, aka "Microsoft Malware Protection Engine Remote Code Execution Vulnerability."
- Affected products
- Defender, Forefront, Malware Protection Engine, Windows 10, Windows 7, Windows 8.1, Windows Rt 8.1, Windows Server 2008
- Microsoft Forefront Security
- All versions
- Microsoft Malware Protection Engine
- β€ 1.1.13701.0
- Microsoft Windows Defender
- All versions
- CVSS 2.0
- 9.3 HIGH
- CVSS 3.1
- 7.8 HIGH
- EPSS
- 73.4% (99th percentile)
- Weakness
- CWE-119
- NVD status
- Modified
- Published
- 2017-05-09
CVE-2017-0290 at NVD
6 known exploits for CVE-2017-0290
Proof-of-concept code and exploit modules indexed by Sploitus
CVE-2017-0290-
π Microsoft Malware Protection Engine Type Confusion
Microsoft Malware Protection Engine RCE (CVE-2017-0290)
Microsoft Security Essentials / SCEP (Microsoft Windows 8/8.1/10 / Windows Server) - 'MsMpEng' Remote Type Confusion
MsMpEng: Remotely Exploitable Type Confusion(CVE-2017-0290)
Microsoft Windows 8 / 8.1 / 10 / Windows Server / SCEP, Microsoft Security Essentials - MsMpEng Remo