Back
CVE-2017-8543
CRITICAL
CISA KEV
Microsoft Windows XP SP3, Windows XP x64 XP2, Windows Server 2003 SP2, Windows Vista, Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allow an attacker to take control of the affected system when Windows Search fails to handle objects in memory, aka "Windows Search Remote Code Execution Vulnerability".
Published: Jun 15, 2017
Modified: Jun 17, 2026
CWE-281
CWE-281
CVSS Metrics
CVSSv3
Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
HIGH
Availability Impact:
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products (17)
| Vendor | Product | Version |
|---|---|---|
| microsoft | windows_10_1507 | - |
| microsoft | windows_10_1507 | - |
| microsoft | windows_10_1511 | - |
| microsoft | windows_10_1511 | - |
| microsoft | windows_10_1607 | - |
| microsoft | windows_10_1607 | - |
| microsoft | windows_10_1703 | - |
| microsoft | windows_10_1703 | - |
| microsoft | windows_7 | - |
| microsoft | windows_8.1 | - |
| microsoft | windows_rt_8.1 | - |
| microsoft | windows_server_2008 | - |
| microsoft | windows_server_2008 | r2 |
| microsoft | windows_server_2008 | r2 |
| microsoft | windows_server_2012 | - |
| microsoft | windows_server_2012 | r2 |
| microsoft | windows_server_2016 | - |
GitHub Security Advisory GHSA-w5g9-xvwm-4qf8
Microsoft Windows XP SP3, Windows XP x64 XP2, Windows Server 2003 SP2, Windows Vista, Windows 7...
References (7)
- http://www.securityfocus.com/bid/98824 Broken Link, Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1038667 Broken Link, Third Party Advisory, VDB Entry
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-8543 Mitigation, Patch, Vendor Advisory
- http://www.securityfocus.com/bid/98824 Broken Link, Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1038667 Broken Link, Third Party Advisory, VDB Entry
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-8543 Mitigation, Patch, Vendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-8543 US Government Resource
Risk Scores
CVSS Score
9.8 / 10
EPSS Score
64.06%
Top 1% most likely to be exploited
Threat Score
88.4 / 100
CISA Known Exploited
Date Added:
2022-05-24
Due Date:
2022-06-14
Required Action:
Apply updates per vendor instructions.
Data Sources
NVD
CISA KEV
EPSS
GitHub