Junglewise Threat Intelligence

CVE-2023-36884: Microsoft Windows Search Remote Code Execution Vulnerability

CVE-2023-36884 · Severity: critical · CVSS 7.5 · Exploited in the wild · Published 2023-07-17

Technologies: Microsoft Windows Server, Microsoft Windows, Microsoft Windows 11, Microsoft Windows 10. Vendors: Microsoft.

Executive brief

Microsoft Windows Search contains a remote code execution vulnerability involving a race condition (CWE-362). An attacker can exploit this by bypassing Mark of the Web (MOTW) defenses using specially crafted files, requiring user interaction to succeed.

Affected products

  • Microsoft Windows 10 1507, 1607, 1809, 21H2, 22H2
  • Microsoft Windows 11 21H2, 22H2
  • Microsoft Windows Server 2008, 2008 R2, 2012, 2012 R2, 2016, 2019, 2022

Timeline

  • 2023-07-17: disclosed
  • 2023-07-17: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2023-07-17: exploited: Reported as exploited in the wild at time of publication

Related threats