[Forgot Password]
Login  Register Subscribe

30389

 
 

423868

 
 

247085

 
 

909

 
 

194218

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

Remote code execution vulnerability in Microsoft malware protection engine

ID: oval:org.secpod.oval:def:40428Date: (C)2017-05-09   (M)2024-03-06
Class: VULNERABILITYFamily: windows




The host is installed with Microsoft malware protection engine before 1.1.13704.0 for Microsoft Forefront Security for SharePoint, Windows Defender or Microsoft Security Essentials and is prone to a remote code execution vulnerability. A flaw is present in the mpengine.dll, which fails to handle a crafted file. Successful exploitation allows attackers to execute arbitrary code in the security context of the LocalSystem account and take control of the system.

Platform:
Microsoft Windows Vista
Microsoft Windows 7
Microsoft Windows 8.1
Microsoft Windows 10
Microsoft Windows Server 2008 R2
Microsoft Windows Server 2012
Microsoft Windows Server 2012 R2
Microsoft Windows Server 2016
Product:
Microsoft Forefront Security for SharePoint
Microsoft Windows Defender
Microsoft Security Essentials
Reference:
CVE-2017-0290
CVE    1
CVE-2017-0290
CPE    4
cpe:/a:microsoft:windows_defender:-
cpe:/a:microsoft:windows_defender
cpe:/a:microsoft:security_essentials
cpe:/a:microsoft:forefront_security_for_sharepoint
...

© SecPod Technologies