Executive brief
A remote code execution vulnerability exists in Microsoft Windows Search when it fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could take full control of the affected system. The flaw is exploitable over the network without authentication or user interaction.
Affected products
- Microsoft Windows XP SP3, x64 XP2
- Microsoft Windows Server 2003 SP2
- Microsoft Windows Vista All versions
- Microsoft Windows 7 SP1
- Microsoft Windows Server 2008 SP2, R2 SP1
- Microsoft Windows 8 All versions
- Microsoft Windows 8.1 All versions
- Microsoft Windows RT 8.1 All versions
- Microsoft Windows Server 2012 Gold, R2
- Microsoft Windows 10 Gold, 1511, 1607, 1703
- Microsoft Windows Server 2016 All versions
Timeline
- 2022-05-24: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2022-05-24: disclosed: Published date in advisory record