July 17, 2023 · Applied Cybernetics Group
CVE-2023-36884 — Microsoft Windows
known ransomware use
Microsoft Windows Search Remote Code Execution Vulnerability
- Added to KEV
2023-07-17- Federal due date
2023-08-29- Vendor
- Microsoft
- Product
- Windows
- EPSS
- 99.9th percentile (score 0.989, as of
2026-09-16) - NVD CVSS v3.1
- 7.5 (HIGH)
- Ransomware use
- Known
- ATT&CK
- T1005 , T1070.001 , T1204.002 , T1486 , T1489 , T1490 , T1553.005 , T1566 · signal rollup
- Upstream
- https://nvd.nist.gov/vuln/detail/CVE-2023-36884
CISA short description
Microsoft Windows Search contains an unspecified vulnerability that could allow an attacker to evade Mark of the Web (MOTW) defenses via a specially crafted malicious file, leading to remote code execution.
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
NVD description
Windows Search Remote Code Execution Vulnerability