« Volver al listado

Microsoft

Microsoft Malware Protection Engine: vulnerabilidades y CVE

Microsoft Malware Protection Engine tiene 31 vulnerabilidades publicadas, 6 de ellas en los últimos 12 meses. 0 son críticas y 2 figuran en el catálogo de explotación activa de CISA.

CVE31
Últimos 12 meses6
Críticas0
Explotadas activamente2

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

🔴 Explotadas activamente (CISA KEV)

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-41091Alta (7.8)0.44%⚠ Explotación activa20 may 2026
Improper link resolution before file access ('link following') in Microsoft Defender allows an authorized attacker to elevate privileges locally.
CVE-2017-8540Alta (7.8)72%⚠ Explotación activa26 may 2017
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1,…

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-69414Alta (7.8)0.33%—14 ago 2026
Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "ShieldBreak ".
CVE-2026-55012Alta (7.8)0.47%—14 jul 2026
Integer overflow or wraparound in Microsoft Defender allows an unauthorized attacker to execute code locally.
CVE-2026-55011Alta (7.8)0.47%—14 jul 2026
Integer underflow (wrap or wraparound) in Microsoft Defender allows an unauthorized attacker to execute code locally.
CVE-2026-50656Alta (7)0.37%—16 jun 2026
Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "RoguePlanet ".
CVE-2026-45584Alta (8.1)0.71%—20 may 2026
Heap-based buffer overflow in Microsoft Defender allows an unauthorized attacker to execute code over a network.
CVE-2026-41091Alta (7.8)0.44%⚠ Explotación activa20 may 2026
Improper link resolution before file access ('link following') in Microsoft Defender allows an authorized attacker to elevate privileges locally.
CVE-2023-33156Alta (7)0.27%—11 jul 2023
Microsoft Defender Elevation of Privilege Vulnerability
CVE-2023-24860Alta (7.5)3.0%—11 abr 2023
Microsoft Defender Denial of Service Vulnerability
CVE-2023-23389Media (6.3)0.26%—14 mar 2023
Microsoft Defender Elevation of Privilege Vulnerability
CVE-2022-37971Alta (7.1)0.65%—11 oct 2022
Microsoft Windows Defender Elevation of Privilege Vulnerability
CVE-2022-24548Media (5.5)3.0%—15 abr 2022
Microsoft Defender Denial of Service Vulnerability
CVE-2021-42298Alta (7.8)5.8%—10 nov 2021
Microsoft Defender Remote Code Execution Vulnerability
CVE-2021-34471Alta (7.8)0.51%—12 ago 2021
Microsoft Defender Elevation of Privilege Vulnerability
CVE-2021-34464Alta (7.8)2.6%—16 jul 2021
Microsoft Defender Remote Code Execution Vulnerability
CVE-2021-34522Alta (7.8)2.7%—14 jul 2021
Microsoft Defender Remote Code Execution Vulnerability
CVE-2021-31985Alta (8.8)7.8%—8 jun 2021
Microsoft Defender Remote Code Execution Vulnerability
CVE-2021-31978Media (5.5)1.2%—8 jun 2021
Microsoft Defender Denial of Service Vulnerability
CVE-2017-11940Alta (7.8)20%—8 dic 2017
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Windows 7 SP1, Windows 8.1, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, 1709 and Windows Server 2016, Windows…
CVE-2017-11937Alta (7.8)28%—7 dic 2017
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Windows 7 SP1, Windows 8.1, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, 1709 and Windows Server 2016, Windows…
CVE-2017-8542Media (5.5)6.0%—26 may 2017
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1,…
CVE-2017-8541Alta (7.8)48%—26 may 2017
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1,…
CVE-2017-8540Alta (7.8)72%⚠ Explotación activa26 may 2017
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1,…
CVE-2017-8539Media (5.5)6.0%—26 may 2017
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1,…
CVE-2017-8538Alta (7.8)50%—26 may 2017
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1,…
CVE-2017-0290Alta (7.8)81%—9 may 2017
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1,…
CVE-2014-2779Media (4.3)13%—18 jun 2014
mpengine.dll in Microsoft Malware Protection Engine before 1.1.10701.0 allows remote attackers to cause a denial of service (system hang) via a crafted file.
CVE-2013-1346Alta (9.3)12%—15 may 2013
mpengine.dll in Microsoft Malware Protection Engine before 1.1.9506.0 on x64 platforms allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted file.
CVE-2011-0037Alta (7.2)1.8%—25 feb 2011
Microsoft Malware Protection Engine before 1.1.6603.0, as used in Microsoft Malicious Software Removal Tool (MSRT), Windows Defender, Security Essentials, Forefront Client Security, Forefront Endpoint Protection 2010,…
CVE-2008-1437Media (5)13%—13 may 2008
Unspecified vulnerability in Microsoft Malware Protection Engine (mpengine.dll) 1.1.3520.0 and 0.1.13.192, as used in multiple Microsoft products, allows context-dependent attackers to cause a denial of service (engine…
CVE-2008-1438Media (5)13%—13 may 2008
Unspecified vulnerability in Microsoft Malware Protection Engine (mpengine.dll) 1.1.3520.0 and 0.1.13.192, as used in multiple Microsoft products, allows context-dependent attackers to cause a denial of service (disk…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1059 Command and Scripting Interpreter1
  2. T1068 Exploitation for Privilege Escalation1
  3. T1203 Exploitation for Client Execution1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Microsoft