Improper input validation in Microsoft products - CVE-2017-8539

 

Improper input validation in Microsoft products - CVE-2017-8539

Published: May 30, 2017


Vulnerability identifier: #VU6800
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-8539
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to an error when processing specially crafted files within Microsoft Malware Protection Engine (mpengine.dll). A remote attacker can create a specially crafted file, pass it to the affected application and trigger a scan timeout.

Successful exploitation of the vulnerability may allow an attacker to disable anti-malware protection on the system until the affected service is restarted.


Affected software

Microsoft Security Essentials
Microsoft Endpoint Protection
Windows Intune Endpoint Protection
Windows Defender
Microsoft Malware Protection Engine
Microsoft Forefront Endpoint Protection
Microsoft Exchange Server

How to mitigate CVE-2017-8539

Update Microsoft Malware Protection Engine (mpengine.dll) to version 1.1.13804.0.


External References

Related Security Bulletins