CVE-2017-8558 is a remote code execution vulnerability in the Microsoft Malware Protection Engine, affecting various Microsoft products including Windows Defender, Forefront, and Security Essentials across multiple Windows versions. This memory corruption flaw, triggered by a specially crafted file, allows an attacker to execute arbitrary code with elevated privileges. With a CVSS score of 7.8 (High) and an EPSS score indicating significant exploitability, it poses a severe risk. While not currently on the CISA KEV list, an ExploitDB entry exists for a heap corruption vulnerability, and it has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:windows_defender:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:endpoint_protection:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:forefront_endpoint_protection:-:*:*:*:*:*:*:* | ||
2010CPE matchmatch criteria | cpe:2.3:a:microsoft:forefront_endpoint_protection:2010:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:security_essentials:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.