Vulnerability Name: CVE-2018-0986 (CCN-141151) Assigned: 2017-12-01 Published: 2018-04-03 Updated: 2021-09-09 Summary: A remote code execution vulnerability exists when the Microsoft Malware Protection Engine does not properly scan a specially crafted file, leading to memory corruption, aka "Microsoft Malware Protection Engine Remote Code Execution Vulnerability." This affects Windows Defender, Windows Intune Endpoint Protection, Microsoft Security Essentials, Microsoft System Center Endpoint Protection, Microsoft Exchange Server, Microsoft System Center, Microsoft Forefront Endpoint Protection. CVSS v3 Severity: 8.8 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H )7.9 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C )Exploitability Metrics: Attack Vector (AV): NetworkAttack Complexity (AC): LowPrivileges Required (PR): NoneUser Interaction (UI): RequiredScope: Scope (S): UnchangedImpact Metrics: Confidentiality (C): HighIntegrity (I): HighAvailibility (A): High
7.8 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H )7.0 High (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C )Exploitability Metrics: Attack Vector (AV): LocalAttack Complexity (AC): LowPrivileges Required (PR): NoneUser Interaction (UI): RequiredScope: Scope (S): UnchangedImpact Metrics: Confidentiality (C): HighIntegrity (I): HighAvailibility (A): High
CVSS v2 Severity: 9.3 High (CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C )Exploitability Metrics: Access Vector (AV): NetworkAccess Complexity (AC): MediumAuthentication (Au): NoneImpact Metrics: Confidentiality (C): CompleteIntegrity (I): CompleteAvailibility (A): Complete
6.8 Medium (CCN CVSS v2 Vector: AV:L/AC:L/Au:S/C:C/I:C/A:C )Exploitability Metrics: Access Vector (AV): LocalAccess Complexity (AC): LowAthentication (Au): Single_InstanceImpact Metrics: Confidentiality (C): CompleteIntegrity (I): CompleteAvailibility (A): Complete
Vulnerability Type: CWE-787 Vulnerability Consequences: Gain Access References: Source: MITRE Type: CNACVE-2018-0986 Source: BID Type: Third Party Advisory, VDB Entry103593 Source: CCN Type: BID-103593Microsoft Malware Protection Engine CVE-2018-0986 Remote Code Execution Vulnerability Source: SECTRACK Type: Third Party Advisory, VDB Entry1040631 Source: XF Type: UNKNOWNms-malware-cve20180986-code-exec(141151) Source: CONFIRM Type: Patch, Vendor Advisoryhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-0986 Source: CCN Type: Microsoft Security TechCenter - April 2018Microsoft SharePoint Elevation of Privilege Vulnerability Source: EXPLOIT-DB Type: EXPLOITOffensive Security Exploit Database [04-05-2018] Source: EXPLOIT-DB Type: Exploit, Third Party Advisory, VDB Entry44402 Vulnerable Configuration: Configuration 1 :cpe:/a:microsoft:exchange_server:2013:-:*:*:*:*:*:* OR cpe:/a:microsoft:exchange_server:2016:-:*:*:*:*:*:* OR cpe:/a:microsoft:security_essentials:-:*:*:*:*:*:*:* Configuration 2 :cpe:/a:microsoft:forefront_endpoint_protection_2010:-:*:*:*:*:*:*:* OR cpe:/a:microsoft:intune_endpoint_protection:-:*:*:*:*:*:*:* OR cpe:/a:microsoft:system_center_endpoint_protection:*:*:*:*:*:*:*:* OR cpe:/a:microsoft:system_center_endpoint_protection:2012:-:*:*:*:*:*:* OR cpe:/a:microsoft:system_center_endpoint_protection:2012:r2:*:*:*:*:*:* Configuration 3 :cpe:/a:microsoft:windows_defender:-:*:*:*:*:*:*:* AND cpe:/o:microsoft:windows_10:1709:*:*:*:*:*:*:* OR cpe:/o:microsoft:windows_8.1:*:*:*:*:*:*:*:* OR cpe:/o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:* OR cpe:/o:microsoft:windows_10:-:*:*:*:*:*:*:* OR cpe:/o:microsoft:windows_10:1511:*:*:*:*:*:*:* OR cpe:/o:microsoft:windows_10:1607:*:*:*:*:*:*:* OR cpe:/o:microsoft:windows_rt_8.1:*:*:*:*:*:*:*:* OR cpe:/o:microsoft:windows_server_1709:-:*:*:*:*:*:x64:* OR cpe:/o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:*:* OR cpe:/o:microsoft:windows_server_2012:*:*:*:*:*:*:*:* OR cpe:/o:microsoft:windows_10:1703:*:*:*:*:*:*:* OR cpe:/o:microsoft:windows_7:-:sp1:*:*:*:*:*:* OR cpe:/o:microsoft:windows_server_2016:*:*:*:*:*:*:*:* Configuration CCN 1 :cpe:/a:microsoft:security_essentials:*:*:*:*:*:*:*:* OR cpe:/a:microsoft:forefront_endpoint_protection:2010:*:*:*:*:*:*:* OR cpe:/a:microsoft:system_center_2012_endpoint_protection:*:*:*:*:*:*:*:* OR cpe:/a:microsoft:exchange_server:2016:*:*:*:*:*:*:* OR cpe:/a:microsoft:intune_endpoint_protection:*:*:*:*:*:*:*:* OR cpe:/a:microsoft:windows_defender:*:*:*:*:*:*:*:* OR cpe:/a:microsoft:exchange_server:2013:*:*:*:*:*:*:* OR cpe:/a:microsoft:system_center_2012_r2_endpoint_protection:*:*:*:*:*:*:*:* AND cpe:/o:microsoft:windows_7:-:sp1:-:*:-:-:x32:* OR cpe:/o:microsoft:windows_7:*:sp1:*:*:*:*:x64:* OR cpe:/o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:x64:* OR cpe:/o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:itanium:* OR cpe:/o:microsoft:windows_server_2012:*:*:*:*:*:*:*:* OR cpe:/o:microsoft:windows_8.1:-:-:-:*:-:-:x32:* OR cpe:/o:microsoft:windows_8.1:*:*:*:*:*:*:x64:* OR cpe:/o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:* OR cpe:/o:microsoft:windows_rt_8.1:*:*:*:*:*:*:*:* OR cpe:/o:microsoft:windows_10:-:*:*:*:*:*:x32:* OR cpe:/o:microsoft:windows_10:*:*:*:*:*:*:x64:* OR cpe:/o:microsoft:windows_server_2016:*:*:*:*:*:*:*:* OR cpe:/o:microsoft:windows_server:1709:*:*:*:*:*:*:* Denotes that component is vulnerable BACK
microsoft exchange server 2013 -
microsoft exchange server 2016 -
microsoft security essentials -
microsoft forefront endpoint protection 2010 -
microsoft intune endpoint protection -
microsoft system center endpoint protection *
microsoft system center endpoint protection 2012 -
microsoft system center endpoint protection 2012 r2
microsoft windows defender -
microsoft windows 10 1709
microsoft windows 8.1 *
microsoft windows server 2012 r2
microsoft windows 10 -
microsoft windows 10 1511
microsoft windows 10 1607
microsoft windows rt 8.1 *
microsoft windows server 2016 1709
microsoft windows server 2008 r2 sp1
microsoft windows server 2012 *
microsoft windows 10 1703
microsoft windows 7 - sp1
microsoft windows server 2016 *
microsoft security essentials *
microsoft forefront endpoint protection 2010
microsoft system center 2012 endpoint protection *
microsoft exchange server 2016
microsoft intune endpoint protection *
microsoft windows defender *
microsoft exchange server 2013
microsoft system center 2012 r2 endpoint protection *
microsoft windows 7 - sp1
microsoft windows 7 * sp1
microsoft windows server 2008 r2
microsoft windows server 2008 r2
microsoft windows server 2012
microsoft windows 8.1 - -
microsoft windows 8.1 *
microsoft windows server 2012 r2
microsoft windows rt 8.1 *
microsoft windows 10 -
microsoft windows 10 *
microsoft windows server 2016
microsoft windows server 1709