CVE-2017-8558
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on 32-bit versions of Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703 does not properly scan a specially crafted file leading to memory corruption. aka "Microsoft Malware Protection Engine Remote Code Execution Vulnerability".
- Affected products
- Malware Protection Engine, Windows 10, Windows 7, Windows 8.1, Windows Rt 8.1, Windows Server 2008, Windows Server 2012
- Microsoft Windows Defender
- All versions
- CVSS 2.0
- 9.3 HIGH
- CVSS 3.1
- 7.8 HIGH
- EPSS
- 42.9% (99th percentile)
- Weakness
- CWE-119
- NVD status
- Modified
- Published
- 2017-06-29
CVE-2017-8558 at NVD
2 known exploits for CVE-2017-8558
Proof-of-concept code and exploit modules indexed by Sploitus