VendorsMicrosoftmalware_protection_engineall versions
Vulnerabilities

Microsoft Malware Protection Engine

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

31CVEs
CVE-2017-0290
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 does not properly scan a specially crafted file leading to memory corruption, aka "Microsoft Malware Protection Engine Remote Code Execution Vulnerability."
Published 2017-05-09 · Modified
9.31 PoCEPSS 0.814
CVE-2017-8540
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016, Microsoft Exchange Server 2013 and 2016, does not properly scan a specially crafted file leading to memory corruption. aka "Microsoft Malware Protection Engine Remote Code Execution Vulnerability", a different vulnerability than CVE-2017-8538 and CVE-2017-8541.
Published 2017-05-26 · Analyzed
9.3KEV1 PoCEPSS 0.719
CVE-2017-8538
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016, Microsoft Exchange Server 2013 and 2016, does not properly scan a specially crafted file leading to memory corruption. aka "Microsoft Malware Protection Engine Remote Code Execution Vulnerability", a different vulnerability than CVE-2017-8540 and CVE-2017-8541.
Published 2017-05-26 · Modified
9.31 PoCEPSS 0.500
CVE-2017-8541
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016, Microsoft Exchange Server 2013 and 2016, does not properly scan a specially crafted file leading to memory corruption. aka "Microsoft Malware Protection Engine Remote Code Execution Vulnerability", a different vulnerability than CVE-2017-8538 and CVE-2017-8540.
Published 2017-05-26 · Modified
9.31 PoCEPSS 0.481
CVE-2006-5270
Integer overflow in the Microsoft Malware Protection Engine (mpengine.dll), as used by Windows Live OneCare, Antigen, Defender, and Forefront Security, allows user-assisted remote attackers to execute arbitrary code via a crafted PDF file.
Published 2007-02-13 · Modified
9.3EPSS 0.303
CVE-2017-11937
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Windows 7 SP1, Windows 8.1, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, 1709 and Windows Server 2016, Windows Server, version 1709, Microsoft Exchange Server 2013 and 2016, does not properly scan a specially crafted file leading to remote code execution. aka "Microsoft Malware Protection Engine Remote Code Execution Vulnerability".
Published 2017-12-07 · Modified
9.3EPSS 0.283
CVE-2017-11940
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Windows 7 SP1, Windows 8.1, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, 1709 and Windows Server 2016, Windows Server, version 1709, Microsoft Exchange Server 2013 and 2016, does not properly scan a specially crafted file leading to remote code execution. aka "Microsoft Malware Protection Engine Remote Code Execution Vulnerability". This is different than CVE-2017-11937.
Published 2017-12-08 · Modified
9.3EPSS 0.198
CVE-2013-1346
mpengine.dll in Microsoft Malware Protection Engine before 1.1.9506.0 on x64 platforms allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted file.
Published 2013-05-15 · Modified
9.3EPSS 0.116
CVE-2021-42298
Microsoft Defender Remote Code Execution Vulnerability
Published 2021-11-10 · Modified
9.3EPSS 0.058
CVE-2021-34522
Microsoft Defender Remote Code Execution Vulnerability
Published 2021-07-14 · Modified
9.3EPSS 0.027
CVE-2021-34464
Microsoft Defender Remote Code Execution Vulnerability
Published 2021-07-16 · Modified
9.3EPSS 0.026
CVE-2021-31985
Microsoft Defender Remote Code Execution Vulnerability
Published 2021-06-08 · Modified
8.8EPSS 0.078
CVE-2026-45584
Microsoft Defender Remote Code Execution Vulnerability
Published 2026-05-20 · Analyzed
8.1EPSS 0.009
CVE-2026-50656
Microsoft Defender Elevation of Privilege Vulnerability
Published 2026-06-16 · Modified
7.8EPSS 0.114
CVE-2026-41091
Microsoft Defender Elevation of Privilege Vulnerability
Published 2026-05-20 · Analyzed
7.8KEVEPSS 0.082
CVE-2026-69414
Microsoft Defender Elevation of Privilege Vulnerability
Published 2026-08-14 · Modified
7.8EPSS 0.006
CVE-2021-34471
Microsoft Defender Elevation of Privilege Vulnerability
Published 2021-08-12 · Modified
7.8EPSS 0.005
CVE-2026-55012
Microsoft Defender Remote Code Execution Vulnerability
Published 2026-07-14 · Analyzed
7.8EPSS 0.004
CVE-2026-55011
Microsoft Defender Remote Code Execution Vulnerability
Published 2026-07-14 · Analyzed
7.8EPSS 0.004
CVE-2023-24860
Microsoft Defender Denial of Service Vulnerability
Published 2023-04-11 · Modified
7.5EPSS 0.030
CVE-2011-0037
Microsoft Malware Protection Engine before 1.1.6603.0, as used in Microsoft Malicious Software Removal Tool (MSRT), Windows Defender, Security Essentials, Forefront Client Security, Forefront Endpoint Protection 2010, and Windows Live OneCare, allows local users to gain privileges via a crafted value of an unspecified user registry key.
Published 2011-02-25 · Modified
7.2EPSS 0.018
CVE-2022-37971
Microsoft Windows Defender Elevation of Privilege Vulnerability
Published 2022-10-11 · Modified
7.1EPSS 0.007
CVE-2023-33156
Microsoft Defender Elevation of Privilege Vulnerability
Published 2023-07-11 · Modified
7.0EPSS 0.003
CVE-2023-23389
Microsoft Defender Elevation of Privilege Vulnerability
Published 2023-03-14 · Modified
6.3EPSS 0.003
CVE-2017-8542
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016, Microsoft Exchange Server 2013 and 2016, does not properly scan a specially crafted file leading to denial of service. aka "Microsoft Malware Protection Engine Denial of Service Vulnerability", a different vulnerability than CVE-2017-8535, CVE-2017-8536, CVE-2017-8537, and CVE-2017-8539.
Published 2017-05-26 · Modified
5.5EPSS 0.060
CVE-2017-8539
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016, Microsoft Exchange Server 2013 and 2016, does not properly scan a specially crafted file leading to denial of service. aka "Microsoft Malware Protection Engine Denial of Service Vulnerability", a different vulnerability than CVE-2017-8535, CVE-2017-8536, CVE-2017-8537, and CVE-2017-8542.
Published 2017-05-26 · Modified
5.5EPSS 0.060
CVE-2022-24548
Microsoft Defender Denial of Service Vulnerability
Published 2022-04-15 · Modified
5.5EPSS 0.030
CVE-2021-31978
Microsoft Defender Denial of Service Vulnerability
Published 2021-06-08 · Modified
5.5EPSS 0.012
CVE-2008-1437
Unspecified vulnerability in Microsoft Malware Protection Engine (mpengine.dll) 1.1.3520.0 and 0.1.13.192, as used in multiple Microsoft products, allows context-dependent attackers to cause a denial of service (engine hang and restart) via a crafted file, a different vulnerability than CVE-2008-1438.
Published 2008-05-13 · Modified
5.0EPSS 0.129
CVE-2008-1438
Unspecified vulnerability in Microsoft Malware Protection Engine (mpengine.dll) 1.1.3520.0 and 0.1.13.192, as used in multiple Microsoft products, allows context-dependent attackers to cause a denial of service (disk space exhaustion) via a file with "crafted data structures" that trigger the creation of large temporary files, a different vulnerability than CVE-2008-1437.
Published 2008-05-13 · Modified
5.0EPSS 0.129
CVE-2014-2779
mpengine.dll in Microsoft Malware Protection Engine before 1.1.10701.0 allows remote attackers to cause a denial of service (system hang) via a crafted file.
Published 2014-06-18 · Modified
4.3EPSS 0.134