Back

CVE-2017-8589

CRITICAL

Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows a remote code execution vulnerability due to the way that Windows Search handles objects in memory, aka "Windows Search Remote Code Execution Vulnerability".

Published: Jul 11, 2017 Modified: Jun 17, 2026
CWE-281

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: UNCHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products (12)

Vendor Product Version
microsoft windows_10 -
microsoft windows_10 1511
microsoft windows_10 1607
microsoft windows_10 1703
microsoft windows_7 *
microsoft windows_8.1 *
microsoft windows_rt_8.1 *
microsoft windows_server_2008 *
microsoft windows_server_2008 r2
microsoft windows_server_2012 -
microsoft windows_server_2012 r2
microsoft windows_server_2016 *

GitHub Security Advisory GHSA-54hw-ww7h-fvm8

Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1,...

Risk Scores

CVSS Score 9.8 / 10
EPSS Score 26.16%

Top 2% most likely to be exploited

Threat Score 47 / 100

Data Sources

NVD EPSS GitHub