CVE-2017-8540: Microsoft Malware Protection Engine
EPSS71.8%KEV 1739件中712位
CVEの年2017追加まで約5年
同じベンダーの登録389
同じ製品の登録1
| 項目 | 内容 |
|---|---|
| ベンダー | Microsoft |
| 製品 | Malware Protection Engine |
| 脆弱性の名前 | Microsoft Malware Protection Engine Improper Restriction of Operations Vulnerability |
| KEVへの追加日 | 2022年3月3日 |
| 米政府機関の対応期限 | 2022年3月24日 |
| ランサムウェアでの悪用 | 不明 |
| CWE | CWE-119 |
CISAの説明(英語)
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016, Microsoft Exchange Server 2013 and 2016, does not properly scan a specially crafted file leading to memory corruption. aka "Microsoft Malware Protection Engine Remote Code Execution Vulnerability".
CISAの既知の悪用された脆弱性カタログ(KEV)のデータです。EPSSはFIRSTが公表する「今後30日以内に悪用が観測される確率」の推定値で、週1回更新しています。対応は必ず各ベンダーの公式情報に従ってください。
このページについて
2022年3月3日にCISAの既知の悪用された脆弱性カタログ(KEV)に追加された、MicrosoftのMalware Protection Engineの脆弱性です。