EXPOSURES › CVE-2017-8543
CVE-2017-8543
HIGH ⌖ ON CISA KEV · EXPLOITEDAn unpatched Windows Search vulnerability allowed remote attackers to execute arbitrary code and take full control of affected systems.
CVE-2017-8543 was an unpatched remote code execution flaw in Windows Search that attackers exploited to gain system control. DIB organizations must ensure all Windows systems are patched against known KEV vulnerabilities to prevent similar compromises. Failure to patch leaves systems vulnerable to exploitation in the wild, leading to potential data breaches and compliance violations.
Shame score — Microsoft failed to patch a known, actively exploited vulnerability for years, allowing widespread exploitation in the wild and demonstrating severe negligence in maintaining system security.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Windows allows an attacker to take control of the affected system when Windows Search fails to handle objects in memory.
| PRODUCT | STATUS |
|---|---|
| Azure Commercial Cloud Microsoft |
Authorized |
| Azure Government (includes Dynamics 365) Microsoft |
Authorized |
| Microsoft Office 365 GCC High Microsoft |
In Process |
| Office 365 Multi-Tenant & Supporting Services Microsoft |
Authorized |