Improper input validation in Microsoft products - CVE-2017-8537

 

Improper input validation in Microsoft products - CVE-2017-8537

Published: May 30, 2017 / Updated: September 14, 2018


Vulnerability identifier: #VU6797
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-8537
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to an error when processing specially crafted files within Microsoft Malware Protection Engine (mpengine.dll). A remote attacker can create a specially crafted file, pass it to the affected application and trigger a scan timeout.

Successful exploitation of the vulnerability may allow an attacker to disable anti-malware protection on the system until the affected service is restarted.


Affected software

Microsoft Security Essentials
Microsoft Endpoint Protection
Windows Intune Endpoint Protection
Windows Defender
Microsoft Malware Protection Engine
Microsoft Forefront Endpoint Protection
Microsoft Exchange Server

How to mitigate CVE-2017-8537

Update Microsoft Malware Protection Engine (mpengine.dll) to version 1.1.13804.0.


Links to Public Exploits and PoC-codes

External References

Related Security Bulletins