Junglewise Threat Intelligence

CVE-2017-8543: Microsoft Windows Search Remote Code Execution Vulnerability

CVE-2017-8543 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2022-05-24

Technologies: Microsoft Windows Server 2008, Microsoft Windows, Microsoft Windows Server 2016, Microsoft Windows Server 2003, Microsoft Windows Vista, Microsoft Windows 10, Microsoft Windows Server 2012, Microsoft Windows XP, Microsoft Windows 7, Microsoft Windows 8.1, Microsoft Windows Rt 8.1. Vendors: Microsoft.

Executive brief

A remote code execution vulnerability exists in Microsoft Windows Search when it fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could take full control of the affected system. The flaw is exploitable over the network without authentication or user interaction.

Affected products

  • Microsoft Windows XP SP3, x64 XP2
  • Microsoft Windows Server 2003 SP2
  • Microsoft Windows Vista All versions
  • Microsoft Windows 7 SP1
  • Microsoft Windows Server 2008 SP2, R2 SP1
  • Microsoft Windows 8 All versions
  • Microsoft Windows 8.1 All versions
  • Microsoft Windows RT 8.1 All versions
  • Microsoft Windows Server 2012 Gold, R2
  • Microsoft Windows 10 Gold, 1511, 1607, 1703
  • Microsoft Windows Server 2016 All versions

Timeline

  • 2022-05-24: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-05-24: disclosed: Published date in advisory record

Related threats