CVE-2014-2779: Input Validation
Published Jun 18, 2014
·Updated
mpengine.dll in Microsoft Malware Protection Engine before 1.1.10701.0 allows remote attackers to cause a denial of service (system hang) via a crafted file.
Affected Software
1 affected component
Microsoft Malware Protection Engine<=1.1.10600.0
Remediation
Patch Available
Event History
Jun 18, 2014
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-2779?
CVE-2014-2779 has a medium severity rating as it can cause denial of service through system hangs.
2
How do I fix CVE-2014-2779?
To fix CVE-2014-2779, update the Microsoft Malware Protection Engine to version 1.1.10701.0 or later.
3
What systems are affected by CVE-2014-2779?
CVE-2014-2779 affects versions of the Microsoft Malware Protection Engine prior to 1.1.10701.0.
4
What type of vulnerability is CVE-2014-2779?
CVE-2014-2779 is a denial of service vulnerability caused by the mpengine.dll component.
5
Who is impacted by the CVE-2014-2779 vulnerability?
Users and organizations utilizing vulnerable versions of Microsoft Malware Protection Engine are impacted by CVE-2014-2779.