Microsoft Malware Protection Engine remote code execution vulnerability - CVE-2018-0986ID: oval:org.secpod.oval:def:44868 | Date: (C)2018-04-04 (M)2024-03-06 |
Class: VULNERABILITY | Family: windows |
A remote code execution vulnerability exists when the Microsoft Malware Protection Engine does not properly scan a specially crafted file, leading to memory corruption. An attacker who successfully exploited this vulnerability could execute arbitrary code in the security context of the LocalSystem account and take control of the system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
Platform: |
Microsoft Windows 7 |
Microsoft Windows 8.1 |
Microsoft Windows 10 |
Microsoft Windows Server 2008 R2 |
Microsoft Windows Server 2012 |
Microsoft Windows Server 2012 R2 |
Microsoft Windows Server 2016 |
Product: |
Microsoft Windows Defender |
Microsoft Security Essentials |