CVE-2017-0290 is a remote code execution vulnerability in the Microsoft Malware Protection Engine, affecting Microsoft Forefront, Defender, and various Windows operating systems. A specially crafted file can lead to memory corruption, allowing an attacker to execute arbitrary code with elevated privileges. This vulnerability has a CVSS score of 7.8 (High) due to its potential for complete compromise of confidentiality, integrity, and availability, though it requires user interaction (UI:R) for exploitation. While not listed on CISA's KEV catalog, exploit code is publicly available on ExploitDB, and it garnered significant community discussion and media coverage at the time of its discovery, including an emergency out-of-band patch from Microsoft.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:forefront_security:-:*:*:*:*:*:*:* | ||
<= 1.1.13701.0CPE matchmatch criteria | cpe:2.3:a:microsoft:malware_protection_engine:*:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:windows_defender:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.