CVE-2017-8536 describes a denial-of-service vulnerability in the Microsoft Malware Protection Engine, impacting various versions of Microsoft Windows, Windows Server, and Exchange Server. This flaw allows an attacker to cause a denial of service by providing a specially crafted file that the engine fails to scan properly. With a CVSS score of 5.5 (Medium), it requires user interaction (UI:R) and local access (AV:L) for exploitation, leading to high availability impact (A:H). While not actively exploited in the wild (KEV: No), public exploit code exists (EDB-42081), and it has garnered significant community discussion and media coverage, indicating awareness among security researchers.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:windows_defender:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:endpoint_protection:-:*:*:*:*:*:*:* | ||
2013CPE matchmatch criteria | cpe:2.3:a:microsoft:exchange_server:2013:-:*:*:*:*:*:* | ||
2016CPE matchmatch criteria | cpe:2.3:a:microsoft:exchange_server:2016:-:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:forefront_endpoint_protection:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.