CVE-2017-8536
Summary
| CVE | CVE-2017-8536 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-05-26 20:29:00 UTC |
| Updated | 2020-04-09 13:14:00 UTC |
| Description | The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016, Microsoft Exchange Server 2013 and 2016, does not properly scan a specially crafted file leading to denial of service. aka "Microsoft Malware Protection Engine Denial of Service Vulnerability", a different vulnerability than CVE-2017-8535, CVE-2017-8537, CVE-2017-8539, and CVE-2017-8542. |
Risk And Classification
Problem Types: CWE-119 | CWE-369 | CWE-476 | CWE-674
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Microsoft | Endpoint Protection | - | All | All | All |
| Application | Microsoft | Endpoint Protection | - | All | All | All |
| Application | Microsoft | Exchange Server | 2013 | - | All | All |
| Application | Microsoft | Exchange Server | 2016 | - | All | All |
| Application | Microsoft | Exchange Server | 2013 | - | All | All |
| Application | Microsoft | Exchange Server | 2016 | - | All | All |
| Application | Microsoft | Forefront Endpoint Protection | - | All | All | All |
| Application | Microsoft | Forefront Endpoint Protection | 2010 | All | All | All |
| Application | Microsoft | Forefront Endpoint Protection | - | All | All | All |
| Application | Microsoft | Forefront Endpoint Protection | 2010 | All | All | All |
| Application | Microsoft | Security Essentials | - | All | All | All |
| Application | Microsoft | Security Essentials | - | All | All | All |
| Application | Microsoft | System Center Endpoint Protection | - | All | All | All |
| Application | Microsoft | System Center Endpoint Protection | - | All | All | All |
| Operating System | Microsoft | Windows 10 | - | All | All | All |
| Operating System | Microsoft | Windows 10 | 1511 | All | All | All |
| Operating System | Microsoft | Windows 10 | 1607 | All | All | All |
| Operating System | Microsoft | Windows 10 | 1703 | All | All | All |
| Operating System | Microsoft | Windows 10 | - | All | All | All |
| Operating System | Microsoft | Windows 10 | 1511 | All | All | All |
| Operating System | Microsoft | Windows 10 | 1607 | All | All | All |
| Operating System | Microsoft | Windows 10 | 1703 | All | All | All |
| Operating System | Microsoft | Windows 7 | - | sp1 | All | All |
| Operating System | Microsoft | Windows 7 | - | sp1 | All | All |
| Operating System | Microsoft | Windows 8.1 | - | All | All | All |
| Operating System | Microsoft | Windows 8.1 | - | All | All | All |
| Application | Microsoft | Windows Defender | - | All | All | All |
| Application | Microsoft | Windows Defender | - | All | All | All |
| Application | Microsoft | Windows Intune Endpoint Protection | All | All | All | All |
| Application | Microsoft | Windows Intune Endpoint Protection | All | All | All | All |
| Operating System | Microsoft | Windows Rt 8.1 | - | All | All | All |
| Operating System | Microsoft | Windows Rt 8.1 | - | All | All | All |
| Operating System | Microsoft | Windows Server 2008 | r2 | sp1 | All | All |
| Operating System | Microsoft | Windows Server 2008 | r2 | sp1 | All | All |
| Operating System | Microsoft | Windows Server 2008 | r2 | sp1 | All | All |
| Operating System | Microsoft | Windows Server 2008 | r2 | sp1 | All | All |
| Operating System | Microsoft | Windows Server 2016 | - | All | All | All |
| Operating System | Microsoft | Windows Server 2016 | - | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Microsoft Malware Protection Engine CVE-2017-8536 Remote Denial of Service Vulnerability | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-8536 | CONFIRM | portal.msrc.microsoft.com | Patch, Vendor Advisory |
| Microsoft MsMpEng - Multiple Crashes While Scanning Malformed Files - Windows dos Exploit | EXPLOIT-DB | www.exploit-db.com | Third Party Advisory, VDB Entry |
| Microsoft Malware Protection Engine File Processing Flaws Let Remote Users Deny Service and Execute Arbitrary Code - SecurityTracker | SECTRACK | www.securitytracker.com | Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.