Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2018-0986

Quick assessment

Affected
Microsoft Windows Defender
Exploitation
High exploitation probability; assess promptly
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Microsoft Exchange Server 2013等都是美国微软(Microsoft)公司的产品。Microsoft Exchange Server 2013是一套电子邮件服务程序,它提供邮件存取、储存、转发,语音邮件,邮件过滤筛选等功能。Security Essentials是一款安全软件,用于防止病毒、间谍软件和其他恶意软件入侵。Malware Protection Engine是其中的一个恶意软件保护引擎。 Microsoft Malware Protection Engine中存在缓冲区

AI Predicted 9.8 Difficulty: Easy EPSS 63.47% · P99

Public Exploits 1

ExploitDB · 1 EDB-44402 [dos]
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2018-0986

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
A remote code execution vulnerability exists when the Microsoft Malware Protection Engine does not properly scan a specially crafted file, leading to memory corruption, aka "Microsoft Malware Protection Engine Remote Code Execution Vulnerability." This affects Windows Defender, Windows Intune Endpoint Protection, Microsoft Security Essentials, Microsoft System Center Endpoint Protection, Microsoft Exchange Server, Microsoft System Center, Microsoft Forefront Endpoint Protection.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Microsoft Malware Protection Engine 缓冲区错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Microsoft Exchange Server 2013等都是美国微软(Microsoft)公司的产品。Microsoft Exchange Server 2013是一套电子邮件服务程序,它提供邮件存取、储存、转发,语音邮件,邮件过滤筛选等功能。Security Essentials是一款安全软件,用于防止病毒、间谍软件和其他恶意软件入侵。Malware Protection Engine是其中的一个恶意软件保护引擎。 Microsoft Malware Protection Engine中存在缓冲区
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Shenlong Deep Dive — AI Deep Analysis

10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.

Affected Products

Vendor Product Affected Versions CPE Subscribe
Microsoft Windows Defender Windows 10 for 32-bit Systems -
Microsoft Windows Intune Endpoint Protection Windows Intune Endpoint Protection -
Microsoft Microsoft Security Essentials Microsoft Security Essentials -
Microsoft Microsoft System Center Endpoint Protection Microsoft System Center Endpoint Protection -
Microsoft Microsoft Exchange Server 2013 -
Microsoft Microsoft System Center 2012 Endpoint Protection -
Microsoft Microsoft Forefront Endpoint Protection 2010 -

II. Public POCs for CVE-2018-0986

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2018-0986

登录查看更多情报信息。

Vendor Advisories for CVE-2018-0986 (3)

Exploits & Public PoCs for CVE-2018-0986 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2018-0986

No comments yet


Leave a comment