CVE-2023-36884

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Jul 11, 2023
Updated: Jan 1, 2025
CWE ID 362

Summary

CVE-2023-36884 is a newly disclosed vulnerability that affects the Windows Search component. Hackers can exploit this Remote Code Execution (RCE) weakness to gain unauthorized access to vulnerable systems. By sending specially crafted messages to the Windows Search service, attackers can execute arbitrary code, potentially leading to serious security consequences. Microsoft has released a patch to address this issue, and it is strongly recommended that all Windows users install it as soon as possible to protect against potential attacks.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share