CVE-2017-8543: Microsoft Windows Search Remote Code Execution Vulnerability

Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2022-05-24. EPSS: 74.2% chance of exploitation in the next 30 days.

Microsoft Windows XP SP3, Windows XP x64 XP2, Windows Server 2003 SP2, Windows Vista, Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allow an attacker to take control of the affected system when Windows Search fails to handle objects in memory, aka "Windows Search Remote Code Execution Vulnerability".

Affected products

  • Microsoft Windows 10 1507: affected versions not specified
  • Microsoft Windows 10 1511: affected versions not specified
  • Microsoft Windows 10 1607: affected versions not specified
  • Microsoft Windows 10 1703: affected versions not specified
  • Microsoft Windows 7: affected versions not specified
  • Microsoft Windows 8.1: affected versions not specified
  • Microsoft Windows Rt 8.1: affected versions not specified
  • Microsoft Windows Server 2008: affected versions not specified; version r2 only
  • Microsoft Windows Server 2012: affected versions not specified; version r2 only
  • Microsoft Windows Server 2016: affected versions not specified

Published 2017-06-15. Last modified 2026-06-17.