KLA11012
Remote code execution vulnerability in the Microsoft Malware Protection Engine
Updated: 05/22/2017
CVSS
?
9.3
Detect date
?
05/08/2017
Severity
?
Critical
Description

An improper way of scanning files was found in the Microsoft Malware Protection. By exploiting this vulnerability malicious users can execute arbitrary code. This vulnerability can be exploited remotely via a specially designed file.


Technical details

To exploit this vulnerability, a malformed file must be scanned by an affected version of the Windows Malware Protection Engine. The specially designed file can be delivered via a website, an email message or an Instant Messenger message.

Affected products

Microsoft Windows 7 Service Pack 1
Microsoft Windows 8.1
Microsoft Windows RT 8.1
Microsoft Windows 10

Solution

Verify that the latest version of the Microsoft Malware Protection Engine and all definition updates for Microsoft antimalware products are being actively downloaded. If necessary, install the update (version of the Microsoft Malware Protection Engine should be 1.1.13704.0 or later).

Original advisories

Microsoft Security Advisory
CVE-2017-0290

Impacts
?
ACE 
[?]
Related products
Windows RT
Microsoft Windows 7
Microsoft Windows 10
CVE-IDS
?

CVE-2017-0290