CVE-2018-0986
HIGH EXPLOITED RANSOMWAREMicrosoft Malware Protection Engine - Remote Code Execution via Crafted File Scan
Title source: llmExploitation Summary
CVE-2018-0986 has been observed exploited in the wild (reported by VulnCheck KEV), including in ransomware campaigns. EIP tracks 1 public exploit from researchers including Google Security Research.
AI-analyzed exploit summary The exploit leverages a signedness issue in Windows Defender's mpengine.dll, derived from outdated unrar code, allowing memory corruption via a crafted RAR file with manipulated PosR and DataSize values in the VMSF_RGB filter.
Description
A remote code execution vulnerability exists when the Microsoft Malware Protection Engine does not properly scan a specially crafted file, leading to memory corruption, aka "Microsoft Malware Protection Engine Remote Code Execution Vulnerability." This affects Windows Defender, Windows Intune Endpoint Protection, Microsoft Security Essentials, Microsoft System Center Endpoint Protection, Microsoft Exchange Server, Microsoft System Center, Microsoft Forefront Endpoint Protection.
Exploits (1)
The exploit leverages a signedness issue in Windows Defender's mpengine.dll, derived from outdated unrar code, allowing memory corruption via a crafted RAR file with manipulated PosR and DataSize values in the VMSF_RGB filter.
References (4)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H