Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2017-8539


The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016, Microsoft Exchange Server 2013 and 2016, does not properly scan a specially crafted file leading to denial of service. aka "Microsoft Malware Protection Engine Denial of Service Vulnerability", a different vulnerability than CVE-2017-8535, CVE-2017-8536, CVE-2017-8537, and CVE-2017-8542.


Published

2017-05-26T20:29:00.397

Last Modified

2025-04-20T01:37:25.860

Status

Deferred

Source

[email protected]

Severity

CVSSv3.0: 5.5 (MEDIUM)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:N/I:N/A:P

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: NONE
  • Availability Impact: PARTIAL
Exploitability Score

8.6

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-119
    CWE-369
    CWE-476
    CWE-674

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application microsoft forefront_security - Yes
Application microsoft malware_protection_engine ≤ 1.1.13704.0 Yes
Application microsoft windows_defender - Yes
Application microsoft exchange_server 2013 No
Application microsoft exchange_server 2016 No
Operating System microsoft windows_10 * No
Operating System microsoft windows_10 1511 No
Operating System microsoft windows_10 1607 No
Operating System microsoft windows_10 1703 No
Operating System microsoft windows_7 - No
Operating System microsoft windows_8.1 * No
Operating System microsoft windows_rt_8.1 - No
Operating System microsoft windows_server_2008 - No
Operating System microsoft windows_server_2008 r2 No
Operating System microsoft windows_server_2012 - No
Operating System microsoft windows_server_2012 r2 No
Operating System microsoft windows_server_2016 - No

References