CVE-2018-0986 is a remote code execution vulnerability in the Microsoft Malware Protection Engine, affecting numerous Microsoft security products including Windows Defender and Exchange Server. This high-severity flaw (CVSS 8.8) allows an unauthenticated attacker to achieve full compromise (confidentiality, integrity, availability) by tricking a user into opening a specially crafted file, leading to memory corruption. While not listed in CISA KEV, public exploit code exists (EDB-44402), and the vulnerability has garnered significant community discussion and media coverage, indicating its potential for exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2013CPE matchmatch criteria | cpe:2.3:a:microsoft:exchange_server:2013:-:*:*:*:*:*:* | ||
2016CPE matchmatch criteria | cpe:2.3:a:microsoft:exchange_server:2016:-:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:security_essentials:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:forefront_endpoint_protection_2010:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:intune_endpoint_protection:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.