CVE-2017-11937 Information
Feb 14, 2021
cve
Description
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Windows 7 SP1 Windows 8.1 Windows RT 8.1 Windows 10 Gold 1511 1607 and 1703 1709 and Windows Server 2016 Windows Server version 1709 Microsoft Exchange Server 2013 and 2016 does not properly scan a specially crafted file leading to remote code execution. aka \Microsoft Malware Protection Engine Remote Code Execution Vulnerability.
CVSS Vector
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Reference
http://www.securityfocus.com/bid/102070 http://www.securitytracker.com/id/1039972 https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-11937
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
REQUIRED
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
7.8
Share on: