Microsoft
Microsoft Malware Protection Engine: vulnerabilidades y CVE
Microsoft Malware Protection Engine tiene 31 vulnerabilidades publicadas, 6 de ellas en los últimos 12 meses. 0 son críticas y 2 figuran en el catálogo de explotación activa de CISA.
CVE31
Últimos 12 meses6
Críticas0
Explotadas activamente2
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-41091 | Alta (7.8) | 0.44% | ⚠ Explotación activa | 20 may 2026 | Improper link resolution before file access ('link following') in Microsoft Defender allows an authorized attacker to elevate privileges locally. |
| CVE-2017-8540 | Alta (7.8) | 72% | ⚠ Explotación activa | 26 may 2017 | The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1,… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-69414 | Alta (7.8) | 0.33% | — | 14 ago 2026 | Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "ShieldBreak ". |
| CVE-2026-55012 | Alta (7.8) | 0.47% | — | 14 jul 2026 | Integer overflow or wraparound in Microsoft Defender allows an unauthorized attacker to execute code locally. |
| CVE-2026-55011 | Alta (7.8) | 0.47% | — | 14 jul 2026 | Integer underflow (wrap or wraparound) in Microsoft Defender allows an unauthorized attacker to execute code locally. |
| CVE-2026-50656 | Alta (7) | 0.37% | — | 16 jun 2026 | Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "RoguePlanet ". |
| CVE-2026-45584 | Alta (8.1) | 0.71% | — | 20 may 2026 | Heap-based buffer overflow in Microsoft Defender allows an unauthorized attacker to execute code over a network. |
| CVE-2026-41091 | Alta (7.8) | 0.44% | ⚠ Explotación activa | 20 may 2026 | Improper link resolution before file access ('link following') in Microsoft Defender allows an authorized attacker to elevate privileges locally. |
| CVE-2023-33156 | Alta (7) | 0.27% | — | 11 jul 2023 | Microsoft Defender Elevation of Privilege Vulnerability |
| CVE-2023-24860 | Alta (7.5) | 3.0% | — | 11 abr 2023 | Microsoft Defender Denial of Service Vulnerability |
| CVE-2023-23389 | Media (6.3) | 0.26% | — | 14 mar 2023 | Microsoft Defender Elevation of Privilege Vulnerability |
| CVE-2022-37971 | Alta (7.1) | 0.65% | — | 11 oct 2022 | Microsoft Windows Defender Elevation of Privilege Vulnerability |
| CVE-2022-24548 | Media (5.5) | 3.0% | — | 15 abr 2022 | Microsoft Defender Denial of Service Vulnerability |
| CVE-2021-42298 | Alta (7.8) | 5.8% | — | 10 nov 2021 | Microsoft Defender Remote Code Execution Vulnerability |
| CVE-2021-34471 | Alta (7.8) | 0.51% | — | 12 ago 2021 | Microsoft Defender Elevation of Privilege Vulnerability |
| CVE-2021-34464 | Alta (7.8) | 2.6% | — | 16 jul 2021 | Microsoft Defender Remote Code Execution Vulnerability |
| CVE-2021-34522 | Alta (7.8) | 2.7% | — | 14 jul 2021 | Microsoft Defender Remote Code Execution Vulnerability |
| CVE-2021-31985 | Alta (8.8) | 7.8% | — | 8 jun 2021 | Microsoft Defender Remote Code Execution Vulnerability |
| CVE-2021-31978 | Media (5.5) | 1.2% | — | 8 jun 2021 | Microsoft Defender Denial of Service Vulnerability |
| CVE-2017-11940 | Alta (7.8) | 20% | — | 8 dic 2017 | The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Windows 7 SP1, Windows 8.1, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, 1709 and Windows Server 2016, Windows… |
| CVE-2017-11937 | Alta (7.8) | 28% | — | 7 dic 2017 | The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Windows 7 SP1, Windows 8.1, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, 1709 and Windows Server 2016, Windows… |
| CVE-2017-8542 | Media (5.5) | 6.0% | — | 26 may 2017 | The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1,… |
| CVE-2017-8541 | Alta (7.8) | 48% | — | 26 may 2017 | The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1,… |
| CVE-2017-8540 | Alta (7.8) | 72% | ⚠ Explotación activa | 26 may 2017 | The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1,… |
| CVE-2017-8539 | Media (5.5) | 6.0% | — | 26 may 2017 | The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1,… |
| CVE-2017-8538 | Alta (7.8) | 50% | — | 26 may 2017 | The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1,… |
| CVE-2017-0290 | Alta (7.8) | 81% | — | 9 may 2017 | The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1,… |
| CVE-2014-2779 | Media (4.3) | 13% | — | 18 jun 2014 | mpengine.dll in Microsoft Malware Protection Engine before 1.1.10701.0 allows remote attackers to cause a denial of service (system hang) via a crafted file. |
| CVE-2013-1346 | Alta (9.3) | 12% | — | 15 may 2013 | mpengine.dll in Microsoft Malware Protection Engine before 1.1.9506.0 on x64 platforms allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted file. |
| CVE-2011-0037 | Alta (7.2) | 1.8% | — | 25 feb 2011 | Microsoft Malware Protection Engine before 1.1.6603.0, as used in Microsoft Malicious Software Removal Tool (MSRT), Windows Defender, Security Essentials, Forefront Client Security, Forefront Endpoint Protection 2010,… |
| CVE-2008-1437 | Media (5) | 13% | — | 13 may 2008 | Unspecified vulnerability in Microsoft Malware Protection Engine (mpengine.dll) 1.1.3520.0 and 0.1.13.192, as used in multiple Microsoft products, allows context-dependent attackers to cause a denial of service (engine… |
| CVE-2008-1438 | Media (5) | 13% | — | 13 may 2008 | Unspecified vulnerability in Microsoft Malware Protection Engine (mpengine.dll) 1.1.3520.0 and 0.1.13.192, as used in multiple Microsoft products, allows context-dependent attackers to cause a denial of service (disk… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.