Vulnerability record · CVE-2017-8540 · published 26 May 2017
CVE-2017-8540: Microsoft Malware Protection Engine out-of-bounds write via crafted file
Microsoft · Malware Protection Engine
The Microsoft Malware Protection Engine, used by Windows Defender, Forefront, Security Essentials, System Center Endpoint Protection, Intune Endpoint Protection and Exchange Server, fails to properly scan a specially crafted file, causing memory corruption. Because the engine runs with high privileges as part of the antimalware service, a successful write primitive can lead to code execution in that context.
Description
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016, Microsoft Exchange Server 2013 and 2016, does not properly scan a specially crafted file leading to memory corruption. aka "Microsoft Malware Protection Engine Remote Code Execution Vulnerability", a different vulnerability than CVE-2017-8538 and CVE-2017-8541.
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityIt is in CISA KEV with a public exploit and very high EPSS, but the vector requires local access and user interaction, and the flaw is from 2017 with a vendor patch available.
What it is
The Microsoft Malware Protection Engine, used by Windows Defender, Forefront, Security Essentials, System Center Endpoint Protection, Intune Endpoint Protection and Exchange Server, fails to properly scan a specially crafted file, causing memory corruption. Because the engine runs with high privileges as part of the antimalware service, a successful write primitive can lead to code execution in that context.
Impact
An attacker who gets a crafted file scanned by the engine can corrupt memory and potentially execute arbitrary code with the privileges of the Malware Protection Engine service, which is typically SYSTEM on Windows hosts.
Attack surface
Reached locally by delivering a specially crafted file that the engine scans; the CVSS vector requires user interaction (UI:R) and no privileges (PR:N), so the victim must cause the file to be scanned, for example by opening or receiving it.
Exploitation
CISA added this to the Known Exploited Vulnerabilities catalog on 2022-03-03 with a 2022-03-24 remediation due date, and EPSS shows a 30-day probability of 0.71961 (99.4th percentile); a public Exploit-DB entry (42088) exists, though no ransomware use is documented.
What to do
- Apply the Microsoft security update for the Malware Protection Engine referenced in the MSRC advisory for CVE-2017-8540.
- Verify the installed engine version is at or above the fixed build across all affected products, including Exchange servers and endpoint protection clients.
- Restrict or filter untrusted file attachments and downloads reaching mail and endpoint scanning paths.
- Where feasible, limit the privileges and exposure of antimalware scanning services on legacy platforms such as Windows Server 2008 and Windows 7.
Detection
- Monitor for crashes or unexpected restarts of the antimalware engine service (MsMpEng) that could indicate malformed-file handling.
- Hunt for processes spawned by the Malware Protection Engine service, which should not normally create child processes.
- Review endpoint telemetry for suspicious files written to disk shortly before engine faults or service restarts.
- Check asset inventory for hosts still running unpatched engine versions on the affected Windows and Exchange platforms.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2017-8540 to the Known Exploited Vulnerabilities catalog on 3 March 2022 as "Microsoft Malware Protection Engine Improper Restriction of Operations Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 24 March 2022.
Affected products
9 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securityfocus.com/bid/98703 | Broken LinkThird Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1038571 | Broken LinkThird Party AdvisoryVDB Entry |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-8540 | MitigationPatchVendor Advisory |
| https://www.exploit-db.com/exploits/42088/ | ExploitThird Party AdvisoryVDB Entry |
| http://www.securityfocus.com/bid/98703 | Broken LinkThird Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1038571 | Broken LinkThird Party AdvisoryVDB Entry |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-8540 | MitigationPatchVendor Advisory |
| https://www.exploit-db.com/exploits/42088/ | ExploitThird Party AdvisoryVDB Entry |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-8540 | US Government Resource |
Track CVE-2017-8540 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2017-8540), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.