Windows Defender Remote Code Execution Vulnerability
A vulnerability in Microsoft's Malware Protection Engine (MMPE) may allow a remote unauthenticated attacker to arbitrarily execute code.
This content has been archived
This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk
Summary
A vulnerability in Microsoft's Malware Protection Engine (MMPE) may allow a remote unauthenticated attacker to arbitrarily execute code.
Threat details
Exploitation of this vulnerability requires a specially crafted file to be scanned by MMPE. This can cause a memory corruption error which an attacker may use to gain full control of the affected system.
At the time of publication there are no known exploits of this vulnerability.
For further information
Remediation steps
CVE Vulnerabilities
Last edited: 17 February 2020 12:57 pm