Back

CVE-2017-11771

CRITICAL

The Microsoft Windows Search component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows a remote code execution vulnerability when it fails to properly handle DNS responses, aka "Windows Search Remote Code Execution Vulnerability".

Published: Oct 13, 2017 Modified: Jun 17, 2026
CWE-20

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: UNCHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products (12)

Vendor Product Version
microsoft windows_10 -
microsoft windows_10 1511
microsoft windows_10 1607
microsoft windows_10 1703
microsoft windows_7 *
microsoft windows_8.1 *
microsoft windows_rt_8.1 *
microsoft windows_server_2008 *
microsoft windows_server_2008 r2
microsoft windows_server_2012 *
microsoft windows_server_2012 r2
microsoft windows_server_2016 *

GitHub Security Advisory GHSA-9vvc-6v43-39qc

The Microsoft Windows Search component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7...

Risk Scores

CVSS Score 9.8 / 10
EPSS Score 64.13%

Top 1% most likely to be exploited

Threat Score 58.4 / 100

Data Sources

NVD EPSS GitHub