CVE-2017-8540 is a remote code execution vulnerability in the Microsoft Malware Protection Engine, affecting various Windows operating systems, Microsoft Forefront, Microsoft Defender, and Microsoft Exchange Server. The vulnerability, rated with a CVSS score of 7.8 (HIGH), allows an attacker to achieve memory corruption by crafting a malicious file that the engine fails to scan properly, leading to high impact on confidentiality, integrity, and availability. This flaw is actively exploited in the wild, as indicated by its inclusion in CISA's KEV catalog, and has garnered significant community attention and media coverage, including an out-of-band update from Microsoft. While no Metasploit or Nuclei exploits are publicly available, an ExploitDB entry details a use-after-free vulnerability related to the GC Engine.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.1.13701.0, < 1.1.13704.0CPE matchmatch criteria | cpe:2.3:a:microsoft:malware_protection_engine:*:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:endpoint_protection:-:*:*:*:*:*:*:* | ||
2013CPE matchmatch criteria | cpe:2.3:a:microsoft:exchange_server:2013:-:*:*:*:*:*:* | ||
2016CPE matchmatch criteria | cpe:2.3:a:microsoft:exchange_server:2016:-:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:forefront_endpoint_protection:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.