CVE-2017-8543
קריטית 9.8 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Microsoft Windows Search Remote Code Execution Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
Microsoft Windows XP SP3, Windows XP x64 XP2, Windows Server 2003 SP2, Windows Vista, Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allow an attacker to take control of the affected system when Windows Search fails to handle objects in memory, aka "Windows Search Remote Code Execution Vulnerability".
מדדים
- CVSS 3.1
-
9.8 (CRITICAL)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 64% (אחוזון 100) נכון ל-25/7/2026
- CWE
- CWE-281
מוצרים מושפעים
microsoft: windows 10 1507; microsoft: windows 10 1511; microsoft: windows 10 1607; microsoft: windows 10 1703; microsoft: windows 7; microsoft: windows 8.1; microsoft: windows rt 8.1; microsoft: windows server 2008; microsoft: windows server 2012; microsoft: windows server 2016
קישורים
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-8543 MitigationPatchVendor Advisory
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-8543 MitigationPatchVendor Advisory
- http://www.securityfocus.com/bid/98824 Broken LinkThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1038667 Broken LinkThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/98824 Broken LinkThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1038667 Broken LinkThird Party AdvisoryVDB Entry
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-201… US Government Resource