CVE-2023-24860 is a Denial of Service vulnerability affecting Microsoft Defender's Malware Protection Engine. With a CVSS score of 7.5 (High), it can be exploited remotely without user interaction, leading to a complete denial of service. While no public exploit code or active exploitation has been observed, its presence on Microsoft's April 2023 Patch Tuesday and limited community discussion indicate awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.1.20200.4CPE matchmatch criteria | cpe:2.3:a:microsoft:malware_protection_engine:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.