ZeroHour

CVE-2017-8543

KEVmass

Unauthenticated Remote Code Execution in Microsoft Windows Search

CISA: Microsoft Windows Search Remote Code Execution Vulnerability

CVSS 3.1
9.8 critical
EPSS
74%p99
Published
()
KEV added
AI analysis

CVE-2017-8543 is a critical (CVSS 9.8) unauthenticated remote code execution flaw in the Windows Search service, which fails to properly handle objects in memory. A remote attacker can trigger it by sending specially crafted messages to the Windows Search service over SMB, or by convincing a user to open a specially crafted file, with no credentials or user interaction required in the network scenario. Successful exploitation gives the attacker complete control of the affected system, including the ability to install programs and to view, change, or delete data. Essentially every Windows client and server release of the era is affected, from Windows XP SP3 and Server 2003 through Windows 10 1703 and Server 2016. The flaw has been exploited in the wild: Microsoft patched it in the June 2017 Patch Tuesday release with reports of active attacks, CISA added it to the KEV catalog on 2022-05-24, and EPSS assigns a 74.3% probability of exploitation within 30 days (99th percentile).

What to do: Install the June 2017 Microsoft security updates (or any later Monthly Quality Rollup) on all affected Windows clients and servers, prioritizing systems with SMB exposed to the internet, which also closes the CISA KEV required action. As an interim mitigation, disabling the Windows Search (WSearch) service blocks exploitation. Inventory for and patch legacy hosts running XP, Server 2003, or Server 2008/2012, which are least likely to have received the fix.

Affected
Microsoft Windows XPSP3 and x64 Edition SP2
Microsoft Windows Server 2003SP2
Microsoft Windows Vistaall supported versions
Microsoft Windows 7SP1
Microsoft Windows 8all supported versions
Microsoft Windows 8.1all supported versions
Microsoft Windows RT 8.1all supported versions
Microsoft Windows Server 2008SP2 and R2 SP1
Microsoft Windows Server 2012all supported versions, plus R2
Microsoft Windows 101507 (Gold), 1511, 1607, 1703
Microsoft Windows Server 2016all supported versions
Estimated exposure
masshundreds of millions of Windows devices (essentially the entire Windows XP through Windows 10 1703 / Server 2016 install base) — The vulnerable Windows Search service ships by default across nearly every Windows client and server release of that era, giving an install base in the hundreds of millions, and 2017-era public internet scans showed millions of hosts…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Microsoft Windows XP SP3, Windows XP x64 XP2, Windows Server 2003 SP2, Windows Vista, Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allow an attacker to take control of the affected system when Windows Search fails to handle objects in memory, aka "Windows Search Remote Code Execution Vulnerability".

CISA Known Exploited Vulnerability
Affected
Microsoft Windows
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
microsoft
Products
windows 10 1507, windows 10 1511, windows 10 1607, windows 10 1703, windows 7, windows 8.1, windows rt 8.1, windows server 2008, windows server 2012, windows server 2016
Weakness
CWE-281
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news