CVE-2017-8538 is a remote code execution vulnerability in the Microsoft Malware Protection Engine, affecting various Windows operating systems, Exchange Server, and Forefront/Defender products. It stems from improper scanning of specially crafted files, leading to memory corruption. With a CVSS score of 7.8 (High), this vulnerability has a low attack complexity and requires user interaction, but can lead to high impact on confidentiality, integrity, and availability. While not listed in CISA's KEV catalog, its high EPSS score and FAUCET Risk Score of 98/100 indicate significant potential for exploitation. Although no Metasploit or Nuclei exploits exist, an ExploitDB entry details multiple crashes, and the vulnerability has garnered significant community discussion and media coverage, including out-of-band updates from Microsoft.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:forefront_security:-:*:*:*:*:*:*:* | ||
<= 1.1.13704.0CPE matchmatch criteria | cpe:2.3:a:microsoft:malware_protection_engine:*:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:windows_defender:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.