May 24, 2022 · Applied Cybernetics Group
CVE-2017-8543 — Microsoft Windows
Microsoft Windows Search Remote Code Execution Vulnerability
- Added to KEV
2022-05-24- Federal due date
2022-06-14- Vendor
- Microsoft
- Product
- Windows
- EPSS
- 99.4th percentile (score 0.851, as of
2026-06-08) - NVD CVSS v3.1
- —
- Ransomware use
- Unknown
- Upstream
- https://nvd.nist.gov/vuln/detail/CVE-2017-8543
CISA short description
Microsoft Windows allows an attacker to take control of the affected system when Windows Search fails to handle objects in memory.
Required action
Apply updates per vendor instructions.