CVE-2018-0986

HIGH EXPLOITED RANSOMWARE

Microsoft Malware Protection Engine - Remote Code Execution via Crafted File Scan

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2018-0986 has been observed exploited in the wild (reported by VulnCheck KEV), including in ransomware campaigns. EIP tracks 1 public exploit from researchers including Google Security Research.

AI-analyzed exploit summary The exploit leverages a signedness issue in Windows Defender's mpengine.dll, derived from outdated unrar code, allowing memory corruption via a crafted RAR file with manipulated PosR and DataSize values in the VMSF_RGB filter.

Description

A remote code execution vulnerability exists when the Microsoft Malware Protection Engine does not properly scan a specially crafted file, leading to memory corruption, aka "Microsoft Malware Protection Engine Remote Code Execution Vulnerability." This affects Windows Defender, Windows Intune Endpoint Protection, Microsoft Security Essentials, Microsoft System Center Endpoint Protection, Microsoft Exchange Server, Microsoft System Center, Microsoft Forefront Endpoint Protection.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Google Security Research · textdoswindows
https://www.exploit-db.com/exploits/44402

The exploit leverages a signedness issue in Windows Defender's mpengine.dll, derived from outdated unrar code, allowing memory corruption via a crafted RAR file with manipulated PosR and DataSize values in the VMSF_RGB filter.

Classification
Working Poc 90%
Attack Type
Dos
Complexity
Moderate
Reliability
Reliable
Target: Windows Defender (mpengine.dll)
No auth needed
Prerequisites: Crafted RAR file with specific VMSF_RGB filter parameters
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (4)

Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1040631
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/103593
Exploit, Third Party Advisory, VDB Entry exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/44402/

Scores

CVSS v3 8.8
EPSS 0.6148
EPSS Percentile 99.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

VulnCheck KEV 2020-02-25
Ransomware Use Confirmed
CWE
CWE-787
Status published
Products (8)
microsoft/exchange_server 2013
microsoft/exchange_server 2016
microsoft/forefront_endpoint_protection_2010
microsoft/intune_endpoint_protection
microsoft/security_essentials
microsoft/system_center_endpoint_protection
microsoft/system_center_endpoint_protection 2012 (2 CPE variants)
microsoft/windows_defender
Published Apr 04, 2018
Tracked Since Feb 18, 2026