CVE-2017-8541 is a remote code execution vulnerability in the Microsoft Malware Protection Engine, affecting various versions of Windows, Windows Server, and Exchange Server. It stems from improper scanning of specially crafted files, leading to memory corruption. With a CVSS score of 7.8 (High) and a FAUCET Risk Score of 98/100, successful exploitation could result in high confidentiality, integrity, and availability impacts, though it requires user interaction. While not listed in CISA's KEV catalog, an ExploitDB entry exists, and it has garnered significant community discussion and media coverage, indicating awareness of its potential.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:forefront_security:-:*:*:*:*:*:*:* | ||
<= 1.1.13704.0CPE matchmatch criteria | cpe:2.3:a:microsoft:malware_protection_engine:*:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:windows_defender:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.