CVE-2017-8543 KEV
9.8
CRITICAL · CVSS 3.1 · EPSS 74.2% (pctl 99)
Patch first
On CISA KEV — known exploited in the wild, due 2022-06-14.
Description
Microsoft Windows XP SP3, Windows XP x64 XP2, Windows Server 2003 SP2, Windows Vista, Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allow an attacker to take control of the affected system when Windows Search fails to handle objects in memory, aka "Windows Search Remote Code Execution Vulnerability".
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 74.16% — more likely to be exploited than 99% of all CVEs |
| Weakness | CWE-281 |
| On CISA KEV | yes — remediate by 2022-06-14 |
| Public exploit | none known |
| Published | 2017-06-15 |
| Last modified | 2026-06-17 |
CISA KEV
| Name | Microsoft Windows Search Remote Code Execution Vulnerability |
|---|---|
| Added | 2022-05-24 |
| Due | 2022-06-14 |
| Vendor / product | Microsoft / Windows |
| Ransomware use | none reported |
Affected (10)
| Vendor | Product |
|---|---|
| microsoft | windows 10 1507 |
| microsoft | windows 10 1511 |
| microsoft | windows 10 1607 |
| microsoft | windows 10 1703 |
| microsoft | windows 7 |
| microsoft | windows 8.1 |
| microsoft | windows rt 8.1 |
| microsoft | windows server 2008 |
| microsoft | windows server 2012 |
| microsoft | windows server 2016 |
References
- http://www.securityfocus.com/bid/98824
- http://www.securitytracker.com/id/1038667
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-8543
- http://www.securityfocus.com/bid/98824
- http://www.securitytracker.com/id/1038667
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-8543
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-8543
→ the Explorer · watch your stack · NVD