Malware Protection Engine

Vendor:

First CVE: Feb 13, 2007 · Active for 19 years

28
Total CVEs
More Total CVEs than 96% of tracked products
2.8
Avg CVEs / Year
Higher CVE frequency than 75% of tracked products
7.2
Avg CVSS
Higher Avg CVSS than 44% of tracked products
7.1%
KEV Rate
Higher KEV Rate than 97% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Malware Protection Engine over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 13, 2007
19 years ago
Most Recent CVE
Jun 16, 2026
38 days ago

CVE Severity & Scoring

Malware Protection Engine28 CVEs
All CVEs352,294 CVEs
MediumHigh
Attack Vector
Local19 (67.9%)
Network3 (10.7%)
Unknown6 (21.4%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low19 (67.9%)
High3 (10.7%)
Unknown6 (21.4%)
User Interaction
None8 (28.6%)
Unknown6 (21.4%)
Required14 (50.0%)
Privileges Required
Low6 (21.4%)
High0 (0.0%)
None16 (57.1%)
Unknown6 (21.4%)

Top CVEs

Signals from CVEs in this product scope (28 CVEs).

28 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows S
May 26, 20177.894YESYES
Improper link resolution before file access ('link following') in Microsoft Defender allows an authorized attacker to elevate privileges locally.
May 20, 20267.880YESNO
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows S
May 9, 20177.876NOYES
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows S
May 26, 20177.864NOYES
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows S
May 26, 20177.864NOYES
Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "RoguePlanet ".
Jun 16, 20267.845NONO
Heap-based buffer overflow in Microsoft Defender allows an unauthorized attacker to execute code over a network.
May 20, 20268.138NONO
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Windows 7 SP1, Windows 8.1, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703,
Dec 7, 20177.837NONO
Integer overflow in the Microsoft Malware Protection Engine (mpengine.dll), as used by Windows Live OneCare, Antigen, Defender, and Forefront Security, allows user-assisted remote
Feb 13, 20079.337NONO
Microsoft Defender Remote Code Execution Vulnerability
Jun 8, 20218.830NONO

Exploit Exposure

Signals from CVEs in this product scope (28 CVEs).

CISA KEV
2 CVEs
7.1% of CVEs· 97th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
4 CVEs
14.3% of CVEs· 89th percentile

Social Chatter

Signals from CVEs in this product scope (28 CVEs).

Media Mentions

Signals from CVEs in this product scope (28 CVEs).

Top CNAs Publishing CVEs For Malware Protection Engine

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
1.1.3520.035.79.2%00
1.1.20000.216.30.3%00
0.1.13.19235.79.2%00