CVE Database
/

CVE-2018-0986

Back to search

CVE-2018-0986

Published: Apr 4, 2018

Modified: Aug 5, 2024

PUBLISHED

Description

A remote code execution vulnerability exists when the Microsoft Malware Protection Engine does not properly scan a specially crafted file, leading to memory corruption, aka "Microsoft Malware Protection Engine Remote Code Execution Vulnerability." This affects Windows Defender, Windows Intune Endpoint Protection, Microsoft Security Essentials, Microsoft System Center Endpoint Protection, Microsoft Exchange Server, Microsoft System Center, Microsoft Forefront Endpoint Protection.

VendorProductVersions

Microsoft

Windows Defender

affected
Windows 10 for 32-bit Systems
affected
Windows 10 for x64-based Systems
affected
Windows 10 Version 1511 for 32-bit Systems
affected
Windows 10 Version 1511 for x64-based Systems
affected
Windows 10 Version 1607 for 32-bit Systems

+20 more versions

Microsoft

Windows Intune Endpoint Protection

affected
Windows Intune Endpoint Protection

Microsoft

Microsoft Security Essentials

affected
Microsoft Security Essentials

Microsoft

Microsoft System Center Endpoint Protection

affected
Microsoft System Center Endpoint Protection

Microsoft

Microsoft Exchange Server

affected
2013
affected
2016

Microsoft

Microsoft System Center

affected
2012 Endpoint Protection
affected
2012 R2 Endpoint Protection

Microsoft

Microsoft Forefront Endpoint Protection

affected
2010

References

1040631
vdb-entry
x_refsource_SECTRACK
103593
vdb-entry
x_refsource_BID
44402
exploit
x_refsource_EXPLOIT-DB

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now