Microsoft issued an emergency Windows Security Update to address a critical flaw, tracked as CVE-2017-11937, that affects the Malware Protection Engine. The critical RCE flaw could be exploited by an attacker to take full control of a victims PC. The fix comes a few days before Microsoft is scheduled to roll out its December Patch Tuesday updates. The vulnerability was reported to Microsoft by the UK’s National Cyber Security Centre (NCSC), a division of the UK GCHQ intelligence agency.”]
Source: https://securityaffairs.co/wordpress/66475/hacking/cve-2017-11937-malware-protection-engine.html