Exploited· due 2022-03-24

CVE-2017-8540

Microsoft Malware Protection Engine

The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016, Microsoft Exchange Server 2013 and 2016, does not properly scan a specially crafted file leading to memory corruption. aka "Microsoft Malware Protection Engine Remote Code Execution Vulnerability".

Exploitation status

  • CISA has confirmed this is being exploited in the wild. That is an observation of real attacks, not a prediction.
  • US federal civilian agencies are required to remediate it by 2022-03-24. That deadline does not bind private companies, but it is a reasonable benchmark for how urgently CISA views it.

Required action

Apply updates per vendor instructions.

CISA’s wording, unedited.

Scoring

CVSS
Not yet scored

Dates

Published
2022-03-03
Added to KEV
2022-03-03
Remediation due
2022-03-24
Sources
CISA KEV