CVE-2017-8542 is a denial-of-service vulnerability affecting the Microsoft Malware Protection Engine, present in various Microsoft Windows, Forefront, Defender, and Exchange Server versions. This flaw allows an attacker to trigger a denial of service by providing a specially crafted file, leading to system instability or unresponsiveness. Rated 5.5 (Medium) on CVSS v3.0, it requires local access and user interaction (e.g., opening a malicious file) to exploit, resulting in high availability impact but no confidentiality or integrity compromise. There is no public exploit code available, nor is it listed in CISA's KEV catalog, indicating no active exploitation. However, it has garnered some community discussion and media coverage, suggesting awareness within the cybersecurity community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:forefront_security:-:*:*:*:*:*:*:* | ||
<= 1.1.13704.0CPE matchmatch criteria | cpe:2.3:a:microsoft:malware_protection_engine:*:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:windows_defender:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.