CVE-2017-8558

high Microsoft
CVSS v3 Base Score
7.8
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
57.8%
Exploitation probability in 30 days
Top 2% most likely to be exploited
Attack Characteristics
Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Confidentiality
High
Integrity
High
Availability
High
Published: June 29, 2017 (3241 days ago)
Last Modified: May 13, 2026
Vendor: Microsoft
Source: NVD

Description

The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on 32-bit versions of Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703 does not properly scan a specially crafted file leading to memory corruption. aka "Microsoft Malware Protection Engine Remote Code Execution Vulnerability".

CWE

CWE-119

Affected Products

microsoft windows defendermicrosoft endpoint protectionmicrosoft forefront endpoint protectionmicrosoft security essentialsmicrosoft windows intune endpoint protection

References