CVE-2017-8540
KEV PoC massMemory Corruption RCE in Microsoft Malware Protection Engine (Defender/Forefront/Exchange)
CISA: Microsoft Malware Protection Engine Improper Restriction of Operations Vulnerability
CVE-2017-8540 is a memory-corruption (out-of-bounds write, CWE-787) flaw in the Microsoft Malware Protection Engine, the shared scan engine behind Windows Defender, Microsoft Security Essentials, Forefront Endpoint Protection, System Center Endpoint Protection, Intune Endpoint Protection, and Exchange Server 2013/2016 on the listed Windows releases. It is triggered when the engine scans a specially crafted file that it does not process properly; because the engine auto-scans files such as email attachments, downloads, and shared locations, an attacker can deliver the malicious file to any scanned location, though Microsoft's 7.8 CVSS score reflects a local attack vector requiring user interaction. Successful exploitation causes memory corruption and code execution in the context of the security software — on Exchange servers, where the engine runs as Local System, this yields full server compromise. Anyone running the affected Windows versions (Windows 7 SP1 through Windows 10 1703, Windows Server 2008 SP2 through 2016, Windows RT 8.1) or Exchange 2013/2016 with an unpatched engine is affected; this is a separate flaw from the related engine bugs CVE-2017-8538 and CVE-2017-8541. It is being exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2022-03-03, it carries a 72% EPSS score (99th percentile), and a public proof of concept is available.
What to do: Apply the patched Malware Protection Engine via Windows Update / Microsoft's engine definition update channel — including on Exchange 2013/2016 servers — per the KEV required action to apply vendor updates, then confirm the installed engine shows the fixed release and that automatic engine updates are enabled. Prioritize internet-facing Exchange servers and legacy hosts running Windows 7 SP1, Windows Server 2008/2008 R2/2012, and Windows 10 1703 or earlier, given confirmed in-the-wild exploitation and the 72% EPSS score.
| microsoft Malware Protection Engine (Windows Defender) | Windows 10 Gold (1507), 1511, 1607, 1703; Windows 8.1; Windows 7 SP1; Windows RT 8.1 |
| microsoft Malware Protection Engine (Forefront/Defender on Windows Server) | Windows Server 2008 SP2; Windows Server 2008 R2 SP1; Windows Server 2012 Gold; Windows Server 2012 R2; Windows Server 2016 |
| microsoft Malware Protection Engine (Microsoft Exchange Server) | Exchange Server 2013; Exchange Server 2016 |
| microsoft Windows Defender | uses the affected engine on the Windows releases listed above |
| microsoft Forefront Endpoint Protection | — |
| microsoft Forefront Security | — |
| microsoft Endpoint Protection | — |
| microsoft System Center Endpoint Protection | — |
| microsoft Intune Endpoint Protection | — |
| Microsoft Security Essentials | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016, Microsoft Exchange Server 2013 and 2016, does not properly scan a specially crafted file leading to memory corruption. aka "Microsoft Malware Protection Engine Remote Code Execution Vulnerability", a different vulnerability than CVE-2017-8538 and CVE-2017-8541.
- Affected
- Microsoft Malware Protection Engine
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- microsoft
- Products
- malware protection engine, endpoint protection, exchange server, forefront endpoint protection, forefront security, intune endpoint protection, security essentials, system center endpoint protection, windows defender
- Weakness
- CWE-787
- Vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H