Synced 19 Jun 2026 07:34 UTC Account
← All products

CVE-2014-2779

MEDIUM severity · CVSS 4.3 · Improper input validation
4.3CVSS MEDIUM

Summary

mpengine.dll in Microsoft Malware Protection Engine before 1.1.10701.0 allows remote attackers to cause a denial of service (system hang) via a crafted file.

Impact & exploitability

Attack vectorNetwork
Attack complexity
Privileges required
User interaction
Confidentiality impactNone
Integrity impactNone
Availability impact
Exploit probability (EPSS)13%

AV:N/AC:M/Au:N/C:N/I:N/A:P

Affected products we track (1)

Recommendation

Apply the vendor fix in your normal patch cycle. Open any affected product above for its exact safe version.

Official patch: https://technet.microsoft.com/library/security/2974294 ↗