Skip to main content

Microsoft Malware Protection Engine Denial of Service Vulnerability

Last Update Date: 18 Jun 2014 12:34 Release Date: 18 Jun 2014 3800 Views

RISK: High Risk

TYPE: Operating Systems - Windows OS

TYPE: Windows OS

A vulnerability was identified in Microsoft Malware Protection Engine. A remote or local user can cause denial of service conditions.

 

A user can create a specially crafted file that, when scanned by the Microsoft Malware Protection Engine, will prevent the engine from monitoring the system(s) until the file is removed and the service is restarted.


Impact

  • Denial of Service

System / Technologies affected

  • Microsoft Forefront Client Security
  • Microsoft Forefront Endpoint Protection 2010
  • Microsoft Forefront Security for SharePoint SP3
  • Microsoft System Center 2012 Endpoint Protection
  • Microsoft System Center 2012 Endpoint Protection SP1
  • Microsoft Malicious Software Removal Tool
  • Microsoft Security Essentials
  • Microsoft Security Essentials Prerelease
  • Windows Defender for Windows 8, Windows 8.1, Windows Server 2012, and Windows Server 2012 R2
  • Windows Defender for Windows RT and Windows RT 8.1
  • Windows Defender for Windows XP, Windows Server 2003, Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2
  • Windows Defender Offline
  • Windows Intune Endpoint Protection 

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.


Vulnerability Identifier


Source


Related Link