QID 92008

Date Published: 2023-04-12

QID 92008: Microsoft Defender Denial of Service (DoS) Vulnerability for April 2023

The Microsoft Malware Protection Engine, mpengine.dll, provides the scanning, detection, and cleaning capabilities for Microsoft antivirus and antispyware software.

Affected Versions / Software:
Microsoft Malware Protection Engine version prior to Version 1.1.20200.4 QID Detection Logic (Authenticated):
The authenticated check looks for the version of "mpengine.dll" file.

Successful exploitation of this vulnerability could lead to Denial of Service Vulnerability

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as High - 6.8 severity.
  • Solution
    Users are advised to check CVE-2023-24860, CVE-2023-24934 for more information.

    CVEs related to QID 92008

    Software Advisories
    Advisory ID Software Component Link
    CVE-2023-24860 URL Logo msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2023-24860
    CVE-2023-24934 URL Logo msrc.microsoft.com/update-guide/vulnerability/CVE-2023-24934