Coverage › CVE-2017-8540
CVE-2017-8540 Unmapped
Microsoft Malware Protection Engine Improper Restriction of Operations Vulnerability
- Vendor / product
- Microsoft — Malware Protection Engine
- Description (CISA)
- The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016, Microsoft Exchange Server 2013 and 2016, does not properly scan a specially crafted file leading to memory corruption. aka "Microsoft Malware Protection Engine Remote Code Execution Vulnerability".
- Added to KEV
- 2022-03-03
- Due date
- 2022-03-24
- Required action
- Apply updates per vendor instructions.
- Known ransomware use
- Unknown
- CWE
- CWE-119
- CISA notes
- https://nvd.nist.gov/vuln/detail/CVE-2017-8540
- Elsewhere
- cve.org · NVD · CISA KEV · JSON
ATT&CK techniques
No public source states how this vulnerability is exploited in ATT&CK terms.
The only authoritative CVE → ATT&CK mapping in the open — CTID's Mappings Explorer, pinned to a KEV snapshot of 2025-07-28 and ATT&CK 16.1 — does not include CVE-2017-8540. CISA's catalogue carries no technique field. kevmap does not infer techniques from the CWE (CWE-119) — here is why — and does not guess.
This page will change state automatically if a mapping is published. What is shown above is everything CISA publishes about the entry.