First published: Thu Jun 29 2017(Updated: )
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on 32-bit versions of Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703 does not properly scan a specially crafted file leading to memory corruption. aka "Microsoft Malware Protection Engine Remote Code Execution Vulnerability".
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Windows Defender | ||
Microsoft Windows 10 | ||
Microsoft Windows 10 | =1511 | |
Microsoft Windows 10 | =1607 | |
Microsoft Windows 10 | =1703 | |
Microsoft Windows 7 | =sp1 | |
Microsoft Windows 8.1 | ||
Microsoft Windows Server 2008 Itanium | =sp2 | |
Microsoft System Center Endpoint Protection | ||
Microsoft Forefront Endpoint Protection | ||
Microsoft Forefront Endpoint Protection | =2010 | |
Microsoft Security Essentials | ||
Microsoft Windows intune endpoint Protection |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-8558 has a high-severity rating due to its potential to allow malware to evade detection by security solutions.
To mitigate CVE-2017-8558, ensure you apply the latest updates and patches provided by Microsoft for your affected software.
CVE-2017-8558 affects various versions of Microsoft Windows, including Windows 7 SP1, Windows 8.1, and several versions of Windows Server.
There are no specific workarounds for CVE-2017-8558; updating the software to a non-vulnerable version is recommended.
CVE-2017-8558 impacts products like Microsoft Windows Defender, Microsoft System Center Endpoint Protection, and Microsoft Forefront Endpoint Protection.