Summary
Detail | |||
---|---|---|---|
Vendor | Microsoft | First view | 2014-06-18 |
Product | Malware Protection Engine | Last view | 2022-04-15 |
Version | 1.1.9402.0 | Type | Application |
Update | - | ||
Edition | %7E%7E%7E%7Ex64%7E | ||
Language | * | ||
Sofware Edition | * | ||
Target Software | * | ||
Target Hardware | * | ||
Other | * | ||
CPE Product | cpe:2.3:a:microsoft:malware_protection_engine |
Activity : Overall
Related : CVE
Date | Alert | Description | |
---|---|---|---|
5.5 | 2022-04-15 | CVE-2022-24548 | Microsoft Defender Denial of Service Vulnerability. |
7.8 | 2021-11-10 | CVE-2021-42298 | Microsoft Defender Remote Code Execution Vulnerability |
7.8 | 2021-08-12 | CVE-2021-34471 | Microsoft Windows Defender Elevation of Privilege Vulnerability |
7.8 | 2021-07-14 | CVE-2021-34522 | Microsoft Defender Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-34464. |
8.8 | 2021-06-08 | CVE-2021-31985 | Microsoft Defender Remote Code Execution Vulnerability |
5.5 | 2021-06-08 | CVE-2021-31978 | Microsoft Defender Denial of Service Vulnerability |
7.8 | 2017-12-08 | CVE-2017-11940 | The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Windows 7 SP1, Windows 8.1, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, 1709 and Windows Server 2016, Windows Server, version 1709, Microsoft Exchange Server 2013 and 2016, does not properly scan a specially crafted file leading to remote code execution. aka "Microsoft Malware Protection Engine Remote Code Execution Vulnerability". This is different than CVE-2017-11937. |
7.8 | 2017-12-07 | CVE-2017-11937 | The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Windows 7 SP1, Windows 8.1, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, 1709 and Windows Server 2016, Windows Server, version 1709, Microsoft Exchange Server 2013 and 2016, does not properly scan a specially crafted file leading to remote code execution. aka "Microsoft Malware Protection Engine Remote Code Execution Vulnerability". |
5.5 | 2017-05-26 | CVE-2017-8542 | The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016, Microsoft Exchange Server 2013 and 2016, does not properly scan a specially crafted file leading to denial of service. aka "Microsoft Malware Protection Engine Denial of Service Vulnerability", a different vulnerability than CVE-2017-8535, CVE-2017-8536, CVE-2017-8537, and CVE-2017-8539. |
7.8 | 2017-05-26 | CVE-2017-8541 | The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016, Microsoft Exchange Server 2013 and 2016, does not properly scan a specially crafted file leading to memory corruption. aka "Microsoft Malware Protection Engine Remote Code Execution Vulnerability", a different vulnerability than CVE-2017-8538 and CVE-2017-8540. |
7.8 | 2017-05-26 | CVE-2017-8540 | The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016, Microsoft Exchange Server 2013 and 2016, does not properly scan a specially crafted file leading to memory corruption. aka "Microsoft Malware Protection Engine Remote Code Execution Vulnerability", a different vulnerability than CVE-2017-8538 and CVE-2017-8541. |
5.5 | 2017-05-26 | CVE-2017-8539 | The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016, Microsoft Exchange Server 2013 and 2016, does not properly scan a specially crafted file leading to denial of service. aka "Microsoft Malware Protection Engine Denial of Service Vulnerability", a different vulnerability than CVE-2017-8535, CVE-2017-8536, CVE-2017-8537, and CVE-2017-8542. |
7.8 | 2017-05-26 | CVE-2017-8538 | The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016, Microsoft Exchange Server 2013 and 2016, does not properly scan a specially crafted file leading to memory corruption. aka "Microsoft Malware Protection Engine Remote Code Execution Vulnerability", a different vulnerability than CVE-2017-8540 and CVE-2017-8541. |
7.8 | 2017-05-09 | CVE-2017-0290 | The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 does not properly scan a specially crafted file leading to memory corruption, aka "Microsoft Malware Protection Engine Remote Code Execution Vulnerability." |
4.3 | 2014-06-18 | CVE-2014-2779 | mpengine.dll in Microsoft Malware Protection Engine before 1.1.10701.0 allows remote attackers to cause a denial of service (system hang) via a crafted file. |
CWE : Common Weakness Enumeration
% | id | Name |
---|---|---|
47% (8) | CWE-119 | Failure to Constrain Operations within the Bounds of a Memory Buffer |
11% (2) | CWE-674 | Uncontrolled Recursion |
11% (2) | CWE-476 | NULL Pointer Dereference |
11% (2) | CWE-369 | Divide By Zero |
5% (1) | CWE-269 | Improper Privilege Management |
5% (1) | CWE-94 | Failure to Control Generation of Code ('Code Injection') |
5% (1) | CWE-20 | Improper Input Validation |
Information Assurance Vulnerability Management (IAVM)
id | Description |
---|---|
2014-A-0090 | Microsoft Malware Protection Engine Denial of Service Vulnerability Severity: Category II - VMSKEY: V0052807 |
Snort® IPS/IDS
Date | Description |
---|---|
2020-09-17 | Microsoft Malware Protection Engine denial-of-service attempt RuleID : 54788 - Type : FILE-EXECUTABLE - Revision : 1 |
2020-09-17 | Microsoft Malware Protection Engine denial-of-service attempt RuleID : 54787 - Type : FILE-EXECUTABLE - Revision : 1 |
2020-03-10 | Microsoft Windows MsMpEng JavaScript garbage collection use after free attempt RuleID : 53060 - Type : OS-WINDOWS - Revision : 1 |
2020-03-10 | Microsoft Windows MsMpEng JavaScript garbage collection use after free attempt RuleID : 53059 - Type : OS-WINDOWS - Revision : 1 |
2020-01-14 | Microsoft Malware Protection Engine type confusion attempt RuleID : 52462 - Type : OS-WINDOWS - Revision : 1 |
2020-01-14 | Microsoft Malware Protection Engine type confusion attempt RuleID : 52461 - Type : OS-WINDOWS - Revision : 1 |
2020-01-14 | Microsoft Malware Protection Engine type confusion attempt RuleID : 52460 - Type : OS-WINDOWS - Revision : 1 |
2020-01-14 | Microsoft Malware Protection Engine type confusion attempt RuleID : 52459 - Type : OS-WINDOWS - Revision : 1 |
2020-01-14 | Microsoft Malware Protection Engine type confusion attempt RuleID : 52458 - Type : OS-WINDOWS - Revision : 1 |
2020-01-14 | Microsoft Malware Protection Engine type confusion attempt RuleID : 52457 - Type : OS-WINDOWS - Revision : 1 |
2020-01-14 | Microsoft Malware Protection Engine type confusion attempt RuleID : 52456 - Type : OS-WINDOWS - Revision : 1 |
2020-01-14 | Microsoft Malware Protection Engine type confusion attempt RuleID : 52455 - Type : OS-WINDOWS - Revision : 1 |
2018-01-11 | Microsoft MsMpEng shrink compressed zip code execution attempt RuleID : 45153 - Type : INDICATOR-COMPROMISE - Revision : 2 |
2018-01-11 | Microsoft MsMpEng shrink compressed zip code execution attempt RuleID : 45152 - Type : INDICATOR-COMPROMISE - Revision : 2 |
2017-07-04 | Microsoft Windows MsMpEng JavaScript garbage collection use after free attempt RuleID : 43057 - Type : OS-WINDOWS - Revision : 3 |
2017-07-04 | Microsoft Windows MsMpEng JavaScript garbage collection use after free attempt RuleID : 43056 - Type : OS-WINDOWS - Revision : 3 |
2017-05-09 | Microsoft Malware Protection Engine type confusion attempt RuleID : 42821-community - Type : OS-WINDOWS - Revision : 2 |
2017-06-13 | Microsoft Malware Protection Engine type confusion attempt RuleID : 42821 - Type : OS-WINDOWS - Revision : 2 |
2017-05-09 | Microsoft Malware Protection Engine type confusion attempt RuleID : 42820-community - Type : OS-WINDOWS - Revision : 2 |
2017-06-13 | Microsoft Malware Protection Engine type confusion attempt RuleID : 42820 - Type : OS-WINDOWS - Revision : 2 |
Nessus® Vulnerability Scanner
id | Description |
---|---|
2017-12-08 | Name: An antimalware application installed on the remote host is affected by a remo... File: microsoft_mpeng_1_1_14405_2.nasl - Type: ACT_GATHER_INFO |
2017-05-31 | Name: An antimalware application installed on the remote host is affected by multip... File: microsoft_mpeng_1_1_13804.nasl - Type: ACT_GATHER_INFO |
2017-05-09 | Name: The remote host has an antimalware application installed that is affected by ... File: smb_kb4022344.nasl - Type: ACT_GATHER_INFO |
2014-06-18 | Name: The remote host has an antimalware application that is affected by a denial o... File: smb_kb2974294.nasl - Type: ACT_GATHER_INFO |