---
cve: "CVE-2017-0290"
severity: "LOW"
cvss: 3.1
epss: "81.6%"
vendor: "Microsoft Corporation"
kev: false
exploited: false
published: "2017-05-09 06:29:00"
tags: [cve, security, low]
source: tsecurity.de CVE-Dossier
exported: "2026-09-08T22:54:00+02:00"
---

# CVE-2017-0290

> 3.1 LOW · 🧪 PoC

## Beschreibung

The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 does not properly scan a specially crafted file leading to memory corruption, aka "Microsoft Malware Protection Engine Remote Code Execution Vulnerability."

## Exploit-Evidenz

- [EDB-41975 — Microsoft Security Essentials / SCEP (Microsoft Windows 8/8.1/10 / Windows Server) - 'MsMpEng' Remote Type Confusion](https://www.exploit-db.com/exploits/41975) ✅

## Referenzen

- <https://arstechnica.com/information-technology/2017/05/windows-defender-nscript-remote-vulnerability/>
- <https://bugs.chromium.org/p/project-zero/issues/detail?id=1252>
- <https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0290>
- <http://www.securitytracker.com/id/1038420>
- <https://www.exploit-db.com/exploits/41975/>
- <http://www.securitytracker.com/id/1038419>
- <https://0patch.blogspot.si/2017/05/0patching-worst-windows-remote-code.html>
- <https://twitter.com/natashenka/status/861748397409058816>
- <https://technet.microsoft.com/library/security/4022344>
- <http://www.securityfocus.com/bid/98330>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2017-0290) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
