CVE-2023-36884CISA KEV
Microsoft Windows Search Remote Code Execution Vulnerability
CISA lists this Microsoft vulnerability as known exploited. Its MSRC release detail is outside this installation's collected history.
CISA catalog record
Microsoft Windows Search contains an unspecified vulnerability that could allow an attacker to evade Mark of the Web (MOTW) defenses via a specially crafted malicious file, leading to remote code execution.
- Product
- Windows
- Added to KEV
- 17 Jul 2023
- Federal remediation due
- 29 Aug 2023
- Known ransomware use
- Yes