ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

8 RCE, DoS holes in Microsoft Malware Protection Engine plugged

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2017-8535
+2 in the same advisory: …8536 …8537
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Wi

The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016, Microsoft Exchange Server 2013 and 2016, does not properly scan a specially crafted file leading to denial of service. aka "Microsoft Malware Protection Engine Denial of Service Vulnerability", a different vulnerability than CVE-2017-8536, CVE-2017-8537, CVE-2017-8539, and CVE-2017-8542.

NVD description · AI analysis pending
5.517%
  • microsoft windows defender
  • microsoft endpoint protection
  • microsoft exchange server
  • +1 more
CVE-2017-8538
+3 in the same advisory: …8541 …8539 …8542
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Wi

The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016, Microsoft Exchange Server 2013 and 2016, does not properly scan a specially crafted file leading to memory corruption. aka "Microsoft Malware Protection Engine Remote Code Execution Vulnerability", a different vulnerability than CVE-2017-8540 and CVE-2017-8541.

NVD description · AI analysis pending
7.8
group max
50%
  • microsoft forefront security
  • microsoft malware protection engine
  • microsoft windows defender
CVE-2017-8540
Memory Corruption RCE in Microsoft Malware Protection Engine (Defender/Forefront/Exchange)

CVE-2017-8540 is a memory-corruption (out-of-bounds write, CWE-787) flaw in the Microsoft Malware Protection Engine, the shared scan engine behind Windows Defender, Microsoft Security Essentials, Forefront Endpoint Protection, System Center Endpoint Protection, Intune Endpoint Protection, and Exchange Server 2013/2016 on the listed Windows releases. It is triggered when the engine scans a specially crafted file that it does not process properly; because the engine auto-scans files such as email attachments, downloads, and shared locations, an attacker can deliver the malicious file to any scanned location, though Microsoft's 7.8 CVSS score reflects a local attack vector requiring user interaction. Successful exploitation causes memory corruption and code execution in the context of the security software — on Exchange servers, where the engine runs as Local System, this yields full server compromise. Anyone running the affected Windows versions (Windows 7 SP1 through Windows 10 1703, Windows Server 2008 SP2 through 2016, Windows RT 8.1) or Exchange 2013/2016 with an unpatched engine is affected; this is a separate flaw from the related engine bugs CVE-2017-8538 and CVE-2017-8541. It is being exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2022-03-03, it carries a 72% EPSS score (99th percentile), and a public proof of concept is available.

Do: Apply the patched Malware Protection Engine via Windows Update / Microsoft's engine definition update channel — including on Exchange 2013/2016 servers — per the KEV required action to apply vendor updates, then confirm the installed engine shows the fixed release and that automatic engine updates are enabled. Prioritize internet-facing Exchange servers and legacy hosts running Windows 7 SP1, Windows Server 2008/2008 R2/2012, and Windows 10 1703 or earlier, given confirmed in-the-wild exploitation and the 72% EPSS score.

7.872% KEV PoC
  • microsoft Malware Protection Engine (Windows Defender) Windows 10 Gold (1507), 1511, 1607, 1703; Windows 8.1; Windows 7 SP1; Windows RT 8.1
  • microsoft Malware Protection Engine (Forefront/Defender on Windows Server) Windows Server 2008 SP2; Windows Server 2008 R2 SP1; Windows Server 2012 Gold; Windows Server 2012 R2; Windows Server 2016
  • microsoft Malware Protection Engine (Microsoft Exchange Server) Exchange Server 2013; Exchange Server 2016
  • +7 more
masshundreds of millions of Windows endpoints and servers (engine is the default Defender/Forefront antimalware scanner on every listed Windows release), plus tens…
Full article299 words · extracted from helpnetsecurity.com · click to collapse

After the discovery and the fixing of a “crazy bad” remote code execution flaw in the Microsoft Malware Protection Engine earlier this month, now comes another MMPE security update that plugs eight flaws that could lead to either remote code execution or to denial of service.

Microsoft Malware Protection Engine flaws

Given that the Microsoft Malware Protection Engine powers a number of Microsoft antimalware software, DoS vulnerabilities should be considered serious, since a successfully exploited vulnerability could prevent the MMPE from monitoring affected systems until the service is restarted.

Microsoft Malware Protection Engine flaws

All these vulnerabilities – CVE-2017-8535, CVE-2017-8536, CVE-2017-8537, CVE-2017-8538, CVE-2017-8539, CVE-2017-8540, CVE-2017-8541, CVE-2017-8542 – have been flagged by Google Project Zero researcher Mateusz Jurczyk, and were discovered through fuzzing.

No specific details were offered about them, except that they can be triggered by a specially crafted file that has to be scanned by an affected version of the MMPE in order for the exploit to work.

Such a file could be offered for download on a website, or delivered via email or instant message. “In addition, an attacker could take advantage of websites that accept or host user-provided content, to upload a specially crafted file to a shared location that is scanned by the Malware Protection Engine running on the hosting server,” Microsoft noted.

The security issues have been fixed in version 1.1.13804.0 of the Microsoft Malware Protection Engine.

The newest version of the engine is usually automatically downloaded and implemented by the security software that uses it.

Still, users who would like to verify whether the latest version of the MMPE and definition updates are being actively downloaded and installed for their Microsoft antimalware products can do so by clicking on the software’s Help tab, then choosing the “About [that specific software]” option.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2017/05/30/microsoft-malware-protection-engine-flaws/