Vulnerability record · CVE-2018-0986 · published 4 April 2018
CVE-2018-0986: Microsoft Malware Protection Engine out-of-bounds write enables remote code execution
Microsoft · Exchange Server
The Microsoft Malware Protection Engine mishandles a specially crafted file during scanning, causing an out-of-bounds write and memory corruption. Because the engine runs with high privileges across Windows Defender, Exchange Server and several endpoint protection products, successful exploitation can lead to code execution in a security-critical process.
Description
A remote code execution vulnerability exists when the Microsoft Malware Protection Engine does not properly scan a specially crafted file, leading to memory corruption, aka "Microsoft Malware Protection Engine Remote Code Execution Vulnerability." This affects Windows Defender, Windows Intune Endpoint Protection, Microsoft Security Essentials, Microsoft System Center Endpoint Protection, Microsoft Exchange Server, Microsoft System Center, Microsoft Forefront Endpoint Protection.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 8.8, public exploit code and very high EPSS make this a serious risk for unpatched systems, though it is not in CISA KEV.
What it is
The Microsoft Malware Protection Engine mishandles a specially crafted file during scanning, causing an out-of-bounds write and memory corruption. Because the engine runs with high privileges across Windows Defender, Exchange Server and several endpoint protection products, successful exploitation can lead to code execution in a security-critical process.
Impact
An attacker who gets a crafted file scanned can corrupt memory and execute arbitrary code in the context of the Malware Protection Engine, which typically runs with SYSTEM-level privileges. This can allow full compromise of the host and, on Exchange or System Center systems, broader environment impact.
Attack surface
The vulnerability is network-reachable (AV:N) with no privileges required (PR:N), but exploitation requires the victim to trigger a scan of the crafted file (UI:R), for example by receiving or opening it. No authentication is needed to deliver the file, but user interaction is required for the engine to process it.
Exploitation
A public exploit exists (Exploit-DB 44402) and EPSS is very high at 0.63 (99th percentile), though the CVE is not listed in CISA KEV. This indicates significant real-world exploitation likelihood despite no confirmed widespread campaign in the record.
What to do
- Apply the Microsoft security update referenced in the MSRC advisory for CVE-2018-0986 as soon as possible.
- Verify that all affected products (Windows Defender, Security Essentials, Forefront/Intune/System Center Endpoint Protection, Exchange Server) have the updated Malware Protection Engine version.
- Where patching is delayed, restrict or monitor automatic scanning of untrusted files and email attachments on affected systems.
- Maintain defense-in-depth controls such as email filtering and endpoint detection to reduce delivery of crafted files.
Detection
- Monitor for unexpected crashes or restarts of the Malware Protection Engine (MsMpEng.exe) or related antivirus services.
- Hunt for suspicious child processes or unusual network connections originating from the Malware Protection Engine process.
- Review endpoint logs for memory corruption indicators or exploit attempts against antivirus/scanning components.
- Track file scanning events involving untrusted attachments or downloads on systems running affected products.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
6 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securityfocus.com/bid/103593 | Third Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1040631 | Third Party AdvisoryVDB Entry |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-0986 | PatchVendor Advisory |
| https://www.exploit-db.com/exploits/44402/ | ExploitThird Party AdvisoryVDB Entry |
| http://www.securityfocus.com/bid/103593 | Third Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1040631 | Third Party AdvisoryVDB Entry |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-0986 | PatchVendor Advisory |
| https://www.exploit-db.com/exploits/44402/ | ExploitThird Party AdvisoryVDB Entry |
Track CVE-2018-0986 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-0986), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.