← Back

Malware Protection Engine

malware_protection_engine

Vendor: Microsoft • 27 CVEs

CVEs (27)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Microsoft
1Malware Protection Engine
May 20, 2026
May 20, 2026
N/A· v4
8.1 HIGH· v3
N/A· v2
Heap-based buffer overflow in Microsoft Defender allows an unauthorized attacker to execute code over a network.
1Microsoft
1Malware Protection Engine
May 20, 2026
May 20, 2026
N/A· v4
7.8 HIGH· v3
N/A· v2
Improper link resolution before file access ('link following') in Microsoft Defender allows an authorized attacker to elevate privileges locally.
1Microsoft
1Malware Protection Engine
Nov 21, 2024
Jul 11, 2023
N/A· v4
7.0 HIGH· v3
N/A· v2
Microsoft Defender Elevation of Privilege Vulnerability
1Microsoft
1Malware Protection Engine
Feb 28, 2025
Apr 11, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Microsoft Defender Denial of Service Vulnerability
1Microsoft
1Malware Protection Engine
Nov 21, 2024
Mar 14, 2023
N/A· v4
6.3 MEDIUM· v3
N/A· v2
Microsoft Defender Elevation of Privilege Vulnerability
1Microsoft
1Malware Protection Engine
Jan 2, 2025
Oct 11, 2022
N/A· v4
7.1 HIGH· v3
N/A· v2
Microsoft Windows Defender Elevation of Privilege Vulnerability
1Microsoft
1Malware Protection Engine
Nov 21, 2024
Apr 15, 2022
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
Microsoft Defender Denial of Service Vulnerability
1Microsoft
1Malware Protection Engine
Nov 21, 2024
Nov 10, 2021
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
Microsoft Defender Remote Code Execution Vulnerability
1Microsoft
1Malware Protection Engine
Nov 21, 2024
Aug 12, 2021
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Microsoft Windows Defender Elevation of Privilege Vulnerability
1Microsoft
1Malware Protection Engine
Nov 21, 2024
Jul 16, 2021
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
Microsoft Defender Remote Code Execution Vulnerability
1Microsoft
1Malware Protection Engine
Nov 21, 2024
Jul 14, 2021
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
Microsoft Defender Remote Code Execution Vulnerability
1Microsoft
1Malware Protection Engine
Nov 21, 2024
Jun 8, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Microsoft Defender Remote Code Execution Vulnerability
1Microsoft
1Malware Protection Engine
Nov 21, 2024
Jun 8, 2021
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Microsoft Defender Denial of Service Vulnerability
1Microsoft
1Malware Protection Engine
May 13, 2026
Dec 8, 2017
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Windows 7 SP1, Windows 8.1, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, 1709 and Windows Server 2016, Windows Se...Show more
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Windows 7 SP1, Windows 8.1, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, 1709 and Windows Server 2016, Windows Server, version 1709, Microsoft Exchange Server 2013 and 2016, does not properly scan a specially crafted file leading to remote code execution. aka "Microsoft Malware Protection Engine Remote Code Execution Vulnerability". This is different than CVE-2017-11937.Show less
1Microsoft
1Malware Protection Engine
May 13, 2026
Dec 7, 2017
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Windows 7 SP1, Windows 8.1, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, 1709 and Windows Server 2016, Windows Se...Show more
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Windows 7 SP1, Windows 8.1, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, 1709 and Windows Server 2016, Windows Server, version 1709, Microsoft Exchange Server 2013 and 2016, does not properly scan a specially crafted file leading to remote code execution. aka "Microsoft Malware Protection Engine Remote Code Execution Vulnerability".Show less
1Microsoft
3Forefront Security
Malware Protection EngineWindows Defender
May 13, 2026
May 26, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1,...Show more
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016, Microsoft Exchange Server 2013 and 2016, does not properly scan a specially crafted file leading to denial of service. aka "Microsoft Malware Protection Engine Denial of Service Vulnerability", a different vulnerability than CVE-2017-8535, CVE-2017-8536, CVE-2017-8537, and CVE-2017-8539.Show less
1Microsoft
3Forefront Security
Malware Protection EngineWindows Defender
May 13, 2026
May 26, 2017
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1,...Show more
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016, Microsoft Exchange Server 2013 and 2016, does not properly scan a specially crafted file leading to memory corruption. aka "Microsoft Malware Protection Engine Remote Code Execution Vulnerability", a different vulnerability than CVE-2017-8538 and CVE-2017-8540.Show less
1Microsoft
9Endpoint Protection
Exchange ServerForefront Endpoint Protection+6 more
Apr 22, 2026
May 26, 2017
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1,...Show more
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016, Microsoft Exchange Server 2013 and 2016, does not properly scan a specially crafted file leading to memory corruption. aka "Microsoft Malware Protection Engine Remote Code Execution Vulnerability", a different vulnerability than CVE-2017-8538 and CVE-2017-8541.Show less
1Microsoft
3Forefront Security
Malware Protection EngineWindows Defender
May 13, 2026
May 26, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1,...Show more
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016, Microsoft Exchange Server 2013 and 2016, does not properly scan a specially crafted file leading to denial of service. aka "Microsoft Malware Protection Engine Denial of Service Vulnerability", a different vulnerability than CVE-2017-8535, CVE-2017-8536, CVE-2017-8537, and CVE-2017-8542.Show less
1Microsoft
3Forefront Security
Malware Protection EngineWindows Defender
May 13, 2026
May 26, 2017
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1,...Show more
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016, Microsoft Exchange Server 2013 and 2016, does not properly scan a specially crafted file leading to memory corruption. aka "Microsoft Malware Protection Engine Remote Code Execution Vulnerability", a different vulnerability than CVE-2017-8540 and CVE-2017-8541.Show less