"Microsoft has posted an out-of-band security update to address a remote code execution flaw in its Malware Protection Engine."
https://www.theregister.co.uk/2017/12/07/microsoft_emergency_update_malware_protection_engine_needs_erm_malware_protection/
Oh noes, not again!
https://www.helpnetsecurity.com/2017/06/27/rce-microsoft-malware-protection-engine/
It's actually the fifth RCE in it this year alone:
https://www.cvedetails.com/vulnerability-list.php?vendor_id=26&product_id=9766&version_id=&page=1&hasexp=0&opdos=0&opec=0&opov=0&opcsrf=0&opgpriv=0&opsqli=0&opxss=0&opdirt=0&opmemc=0&ophttprs=0&opbyp=0&opfileinc=0&opginf=0&cvssscoremin=0&cvssscoremax=0&year=0&month=0&cweid=0&order=3&trc=15