Critical vulnerability found in Microsoft Malware Protection Engine
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2017-11937 | The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Windows 7 SP1, Windows 8.1, Windows RT 8.1, Windows 10 Gold, 15 The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Windows 7 SP1, Windows 8.1, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, 1709 and Windows Server 2016, Windows Server, version 1709, Microsoft Exchange Server 2013 and 2016, does not properly scan a specially crafted file leading to remote code execution. aka "Microsoft Malware Protection Engine Remote Code Execution Vulnerability". NVD description · AI analysis pending | 7.8 | 28% |
| — |
Full article636 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
The vulnerability was found and reported by an organization under GCHQ.
Microsoft revealed a critical vulnerability in the Microsoft Malware Protection Engine (MPE) on Thursday that allows an attacker to take full control of a target’s computer. A vast array of Microsoft security products are affected, including Windows Defender for Windows 10.
The Microsoft Malware Protection Engine provides the core cybersecurity capabilities for Microsoft anti-virus and anti-spyware programs in all of the company’s products.
The vulnerability is fixed and patches are going out to users now. There is no sign it was exploited in the real world, according to Microsoft.
The vulnerability is exploited when a specially crafted file is scanned by the Microsoft Malware Protection Engine that then allows an attacker to gain remote code execution. The report from Microsoft warned “there are many ways that an attacker could place a specially crafted file in a location that is scanned” by the vulnerable software. A dangerous file could be delivered by a website, email and messengers.
If a victim has real-time protection turned on, MPE will automatically scan and be exploited.
“An attacker could take advantage of websites that accept or host user-provided content, to upload a specially crafted file to a shared location that is scanned by the Malware Protection Engine running on the hosting server,” the report said.
The incident reignited criticism from cybersecurity experts against the way Microsoft built their security products.
“Microsoft exposed their users to a lot of risks when they released Windows Defender without a sandbox,” Andy Ying, a developer at the security firm Trail of Bits, wrote earlier this year. “This surprised me. Sandboxing is one of the most effective security-hardening techniques. Why did Microsoft sandbox other high-value attack surfaces such as the JIT code in Microsoft Edge, but leave Windows Defender undefended?”
Sandboxing is the security mechanism for strictly separating specific software from the rest the computer in order to mitigate potential critical vulnerabilities from affecting the whole of the operating system. It’s considered a significant security measure for software with “unencumbered access to its host machine,” Ying wrote.
Today’s disclosure brought out the same criticisms. Here is Google’s Tavis Ormandy:
Ying published an open source sandboxed version of Windows Defender in August 2017.
Microsoft did not respond to a request for comment.
Thursday’s vulnerability, numbered CVE-2017-11937, was found and reported to Microsoft by the U.K.’s National Cyber Security Centre, a cybersecurity-focused government organization under the umbrella of the United Kingdom’s GCHQ signals intelligence agency.
Microsoft Malware Protection Engine has seen multiple significant vulnerabilities in recent months including seven found by Google’s Project Zero.
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
Jail time for Maine child in 764 marks turning point in federal law enforcement
Technology
Threats
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/critical-vulnerability-hits-microsoft-malware-protection-engine/