QID 92039

Date Published: 2023-07-12

QID 92039: Microsoft Defender Elevation of Privilege Vulnerability for July 2023

The Microsoft Malware Protection Engine, mpengine.dll, provides the scanning, detection, and cleaning capabilities for Microsoft antivirus and antispyware software.

Affected Versions / Software:
Microsoft Malware Protection Engine version prior to Version 1.1.23050.3 QID Detection Logic (Authenticated):
The authenticated check looks for the version of "mpengine.dll" file.

Successful exploitation of this vulnerability requires an attacker to win a race condition.

  • CVSS V3 rated as High - 7 severity.
  • CVSS V2 rated as High - 6.8 severity.
  • Solution
    Users are advised to check CVE-2023-33156 for more information.

    CVEs related to QID 92039

    Software Advisories
    Advisory ID Software Component Link
    CVE-2023-33156 URL Logo msrc.microsoft.com/update-guide/vulnerability/CVE-2023-33156