HIGH · 8.8

CVE-2018-0986

A remote code execution vulnerability exists when the Microsoft Malware Protection Engine does not properly scan a specially crafted file, leading to memory corruption, aka "Microsoft Malware Protecti...

Vulnerability Description

A remote code execution vulnerability exists when the Microsoft Malware Protection Engine does not properly scan a specially crafted file, leading to memory corruption, aka "Microsoft Malware Protection Engine Remote Code Execution Vulnerability." This affects Windows Defender, Windows Intune Endpoint Protection, Microsoft Security Essentials, Microsoft System Center Endpoint Protection, Microsoft Exchange Server, Microsoft System Center, Microsoft Forefront Endpoint Protection.

CVSS Score

8.8

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
MicrosoftExchange Server2013
MicrosoftSecurity Essentials-
MicrosoftForefront Endpoint Protection 2010-
MicrosoftIntune Endpoint Protection-
MicrosoftSystem Center Endpoint ProtectionAll versions
MicrosoftWindows Defender-
MicrosoftWindows 10-
MicrosoftWindows 7-
MicrosoftWindows 8.1All versions
MicrosoftWindows Rt 8.1All versions
MicrosoftWindows Server 2008r2
MicrosoftWindows Server 2012All versions
MicrosoftWindows Server 2016All versions

Related Weaknesses (CWE)

References

FAQ

What is CVE-2018-0986?

CVE-2018-0986 is a vulnerability with a CVSS score of 8.8 (HIGH). A remote code execution vulnerability exists when the Microsoft Malware Protection Engine does not properly scan a specially crafted file, leading to memory corruption, aka "Microsoft Malware Protecti...

How severe is CVE-2018-0986?

CVE-2018-0986 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2018-0986?

Check the references section above for vendor advisories and patch information. Affected products include: Microsoft Exchange Server, Microsoft Security Essentials, Microsoft Forefront Endpoint Protection 2010, Microsoft Intune Endpoint Protection, Microsoft System Center Endpoint Protection.