Microsoft Malware Protection Engine Denial of Service Vulnerability
Last Update Date:
18 Jun 2014 12:34
Release Date:
18 Jun 2014
3800
Views
RISK: High Risk
TYPE: Operating Systems - Windows OS
A vulnerability was identified in Microsoft Malware Protection Engine. A remote or local user can cause denial of service conditions.
A user can create a specially crafted file that, when scanned by the Microsoft Malware Protection Engine, will prevent the engine from monitoring the system(s) until the file is removed and the service is restarted.
Impact
- Denial of Service
System / Technologies affected
- Microsoft Forefront Client Security
- Microsoft Forefront Endpoint Protection 2010
- Microsoft Forefront Security for SharePoint SP3
- Microsoft System Center 2012 Endpoint Protection
- Microsoft System Center 2012 Endpoint Protection SP1
- Microsoft Malicious Software Removal Tool
- Microsoft Security Essentials
- Microsoft Security Essentials Prerelease
- Windows Defender for Windows 8, Windows 8.1, Windows Server 2012, and Windows Server 2012 R2
- Windows Defender for Windows RT and Windows RT 8.1
- Windows Defender for Windows XP, Windows Server 2003, Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2
- Windows Defender Offline
- Windows Intune Endpoint Protection
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- The vendor has issued a fix (1.1.10701.0).
https://technet.microsoft.com/en-us/library/security/2974294
Vulnerability Identifier
Source
Related Link
Share with