CVE-2017-8543
KEVmassUnauthenticated Remote Code Execution in Microsoft Windows Search
CISA: Microsoft Windows Search Remote Code Execution Vulnerability
CVE-2017-8543 is a critical (CVSS 9.8) unauthenticated remote code execution flaw in the Windows Search service, which fails to properly handle objects in memory. A remote attacker can trigger it by sending specially crafted messages to the Windows Search service over SMB, or by convincing a user to open a specially crafted file, with no credentials or user interaction required in the network scenario. Successful exploitation gives the attacker complete control of the affected system, including the ability to install programs and to view, change, or delete data. Essentially every Windows client and server release of the era is affected, from Windows XP SP3 and Server 2003 through Windows 10 1703 and Server 2016. The flaw has been exploited in the wild: Microsoft patched it in the June 2017 Patch Tuesday release with reports of active attacks, CISA added it to the KEV catalog on 2022-05-24, and EPSS assigns a 74.3% probability of exploitation within 30 days (99th percentile).
What to do: Install the June 2017 Microsoft security updates (or any later Monthly Quality Rollup) on all affected Windows clients and servers, prioritizing systems with SMB exposed to the internet, which also closes the CISA KEV required action. As an interim mitigation, disabling the Windows Search (WSearch) service blocks exploitation. Inventory for and patch legacy hosts running XP, Server 2003, or Server 2008/2012, which are least likely to have received the fix.
| Microsoft Windows XP | SP3 and x64 Edition SP2 |
| Microsoft Windows Server 2003 | SP2 |
| Microsoft Windows Vista | all supported versions |
| Microsoft Windows 7 | SP1 |
| Microsoft Windows 8 | all supported versions |
| Microsoft Windows 8.1 | all supported versions |
| Microsoft Windows RT 8.1 | all supported versions |
| Microsoft Windows Server 2008 | SP2 and R2 SP1 |
| Microsoft Windows Server 2012 | all supported versions, plus R2 |
| Microsoft Windows 10 | 1507 (Gold), 1511, 1607, 1703 |
| Microsoft Windows Server 2016 | all supported versions |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Microsoft Windows XP SP3, Windows XP x64 XP2, Windows Server 2003 SP2, Windows Vista, Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allow an attacker to take control of the affected system when Windows Search fails to handle objects in memory, aka "Windows Search Remote Code Execution Vulnerability".
- Affected
- Microsoft Windows
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- microsoft
- Products
- windows 10 1507, windows 10 1511, windows 10 1607, windows 10 1703, windows 7, windows 8.1, windows rt 8.1, windows server 2008, windows server 2012, windows server 2016
- Weakness
- CWE-281
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H