This application requires Javascript for optimal performance.

MS.Malware.Protection.Engine.File.Processing.DoS

Release Date

Apr 01, 2009

Severity

medium

Impact

Denial of Service: Remote attackers can crash vulnerable systems.

Description

This indicates an attack attempt against a denial of service (DoS) vulnerability in Microsoft Malware Protection Engine.

The vulnerability is caused by an error when the vulnerable software handles a specially crafted Portable Executable (PE) files compressed with PECompact. It allows a remote attacker to crash the Malware Protection Engine.

Affected Products

Microsoft Windows Live OneCare 0
Microsoft Windows Defender x64 Edition 0
Microsoft Windows Defender 0
Microsoft Standalone System Sweeper 0
Microsoft Forefront Security for SharePoint Server 1.0
Microsoft Forefront Security for Exchange Server 1.0
Microsoft Forefront Client Security 0
Microsoft Antigen for SMTP Gateway 9
Microsoft Antigen for Exchange 9

Recommended Actions

Apply patch, available from the website:
http://www.microsoft.com/technet/security/Bulletin/MS08-029.mspx

Coverage

IPS
VCM

Common Vulnerabilities and Exposures (CVE)

CVE-2008-1437

Reference/s

http://www.frsirt.com/english/advisories/2008/1476 (FrSIRT)
http://technet.microsoft.com/en-us/security/bulletin/ms08-029.mspx (MS-ID)
http://www.securityfocus.com/bid/29060 (BugTraq)

Reference: VID-15595