Vulnerability Description
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Windows 7 SP1, Windows 8.1, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, 1709 and Windows Server 2016, Windows Server, version 1709, Microsoft Exchange Server 2013 and 2016, does not properly scan a specially crafted file leading to remote code execution. aka "Microsoft Malware Protection Engine Remote Code Execution Vulnerability".
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Microsoft | Malware Protection Engine | <= 1.1.14306.0 |
| Microsoft | Exchange Server | 2013 |
| Microsoft | Forefront Endpoint Protection 2010 | - |
| Microsoft | Windows Defender | - |
| Microsoft | Windows 10 | - |
| Microsoft | Windows 7 | - |
| Microsoft | Windows 8.1 | - |
| Microsoft | Windows Rt 8.1 | - |
| Microsoft | Windows Server 2016 | - |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/102070Third Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1039972Third Party AdvisoryVDB Entry
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-1193PatchVendor Advisory
- http://www.securityfocus.com/bid/102070Third Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1039972Third Party AdvisoryVDB Entry
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-1193PatchVendor Advisory
FAQ
What is CVE-2017-11937?
CVE-2017-11937 is a vulnerability with a CVSS score of 7.8 (HIGH). The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Windows 7 SP1, Windows 8.1, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, 1709 and Windows Ser...
How severe is CVE-2017-11937?
CVE-2017-11937 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-11937?
Check the references section above for vendor advisories and patch information. Affected products include: Microsoft Malware Protection Engine, Microsoft Exchange Server, Microsoft Forefront Endpoint Protection 2010, Microsoft Windows Defender, Microsoft Windows 10.