
CVE-2020-1002
https://notcve.org/view.php?id=CVE-2020-1002
15 Apr 2020 — An elevation of privilege vulnerability exists when the MpSigStub.exe for Defender allows file deletion in arbitrary locations.To exploit the vulnerability, an attacker would first have to log on to the system, aka 'Microsoft Defender Elevation of Privilege Vulnerability'. Hay una vulnerabilidad de elevación de privilegios cuando el archivo MpSigStub.exe para Defender permite la eliminación de archivos en ubicaciones arbitrarias. Para explotar la vulnerabilidad, un atacante tendría primero que registrarse e... • https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1002 •

CVE-2019-1255
https://notcve.org/view.php?id=CVE-2019-1255
23 Sep 2019 — A denial of service vulnerability exists when Microsoft Defender improperly handles files, aka 'Microsoft Defender Denial of Service Vulnerability'. Se presenta una vulnerabilidad de denegación de servicio cuando Microsoft Defender maneja inapropiadamente los archivos, también se conoce como "Microsoft Defender Denial of Service Vulnerability". • https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1255 •

CVE-2019-1161 – Microsoft Defender Elevation of Privilege Vulnerability
https://notcve.org/view.php?id=CVE-2019-1161
14 Aug 2019 — An elevation of privilege vulnerability exists when the MpSigStub.exe for Defender allows file deletion in arbitrary locations. To exploit the vulnerability, an attacker would first have to log on to the system. An attacker could then run a specially crafted command that could exploit the vulnerability and delete protected files on an affected system once MpSigStub.exe ran again. The update addresses the vulnerability and blocks the arbitrary deletion. Existe una vulnerabilidad de elevación de privilegios c... • https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1161 •

CVE-2018-0986 – Microsoft Windows Defender - 'mpengine.dll' Memory Corruption
https://notcve.org/view.php?id=CVE-2018-0986
04 Apr 2018 — A remote code execution vulnerability exists when the Microsoft Malware Protection Engine does not properly scan a specially crafted file, leading to memory corruption, aka "Microsoft Malware Protection Engine Remote Code Execution Vulnerability." This affects Windows Defender, Windows Intune Endpoint Protection, Microsoft Security Essentials, Microsoft System Center Endpoint Protection, Microsoft Exchange Server, Microsoft System Center, Microsoft Forefront Endpoint Protection. Existe una vulnerabilidad de... • https://www.exploit-db.com/exploits/44402 • CWE-787: Out-of-bounds Write •

CVE-2017-4028 – SB10193 - consumer and corporate products - Maliciously misconfigured registry vulnerability
https://notcve.org/view.php?id=CVE-2017-4028
03 Apr 2018 — Maliciously misconfigured registry vulnerability in all Microsoft Windows products in McAfee consumer and corporate products allows an administrator to inject arbitrary code into a debugged McAfee process via manipulation of registry parameters. Vulnerabilidad de registro maliciosamente configurado en todos los productos Microsoft Windows en productos para consumidores y empresas de McAfee permite que un administrador inyecte código arbitrario en un proceso McAffee depurado mediante la manipulación de parám... • http://www.securityfocus.com/bid/97958 • CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') •

CVE-2017-11940 – Microsoft Security Bulletin Summary for December, 2017
https://notcve.org/view.php?id=CVE-2017-11940
08 Dec 2017 — The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Windows 7 SP1, Windows 8.1, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, 1709 and Windows Server 2016, Windows Server, version 1709, Microsoft Exchange Server 2013 and 2016, does not properly scan a specially crafted file leading to remote code execution. aka "Microsoft Malware Protection Engine Remote Code Execution Vulnerability". This is different than CVE-2017-11937. Microsoft Malware Protection En... • http://www.securityfocus.com/bid/102104 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2017-11937 – Microsoft Security Bulletin Summary for December, 2017
https://notcve.org/view.php?id=CVE-2017-11937
06 Dec 2017 — The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Windows 7 SP1, Windows 8.1, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, 1709 and Windows Server 2016, Windows Server, version 1709, Microsoft Exchange Server 2013 and 2016, does not properly scan a specially crafted file leading to remote code execution. aka "Microsoft Malware Protection Engine Remote Code Execution Vulnerability". Microsoft Malware Protection Engine que se ejecute en Microsoft Forefr... • http://www.securityfocus.com/bid/102070 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2017-13680
https://notcve.org/view.php?id=CVE-2017-13680
06 Nov 2017 — Prior to SEP 12.1 RU6 MP9 & SEP 14 RU1 Symantec Endpoint Protection Windows endpoint can encounter a situation whereby an attacker could use the product's UI to perform unauthorized file deletes on the resident file system. En versiones anteriores a SEP 12.1 RU6 MP9 SEP 14 RU1, el endpoint Symantec Endpoint Protection Windows puede encontrarse con una situación en la que un atacante podría emplear la interfaz de usuario del producto para realizar borrados no autorizados de archivos en el sistema de archivos... • http://www.securityfocus.com/bid/101503 •

CVE-2017-8558 – Microsoft MsMpEng - mpengine x86 Emulator Heap Corruption in VFS API
https://notcve.org/view.php?id=CVE-2017-8558
23 Jun 2017 — The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on 32-bit versions of Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703 does not properly scan a specially crafted file leading to memory corruption. aka "Microsoft Malware Protection Engine Remote Code Execution Vulnerability". El Motor de Protección de Malware de Microsoft corriendo en Microsoft Forefron... • https://www.exploit-db.com/exploits/42264 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2017-8535 – Microsoft MsMpEng - Multiple Crashes While Scanning Malformed Files
https://notcve.org/view.php?id=CVE-2017-8535
26 May 2017 — The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016, Microsoft Exchange Server 2013 and 2016, does not properly scan a specially crafted file leading to denial of service. aka "Microsoft Malware Protection Engine Denial of Service Vulnerability", a different vulnerability than CVE... • https://packetstorm.news/files/id/142713 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer CWE-369: Divide By Zero CWE-476: NULL Pointer Dereference CWE-674: Uncontrolled Recursion •