LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2023-36884: Microsoft Windows Search Remote Code Execution Vulnerability

RBRecent Breaches Vulnerability Intelligence·Jul 17, 2023
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
Aug 29, 2023
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2023-36884 to its Known Exploited Vulnerabilities catalog on Jul 17, 2023, with a federal patch deadline of Aug 29, 2023 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

Microsoft Windows Search contains an unspecified vulnerability that could allow an attacker to evade Mark of the Web (MOTW) defenses via a specially crafted malicious file, leading to remote code…

CVE-2023-36884 is a remote code execution vulnerability in Microsoft Windows Search. It allows an attacker to evade Mark of the Web (MOTW) defenses with a specially crafted malicious file, which can lead to code running on the target system. This matters because Windows Search is a core component of Microsoft Windows, so successful abuse can give an attacker a foothold for further activity. Public reporting also indicates known ransomware use of this vulnerability, raising the stakes for any unpatched environment.

Defenders should treat this as a high-priority item for inventory and remediation. Exact affected builds, severity metrics, and exploitation prerequisites must be confirmed against the vendor advisory, as those details are not restated here.

How it works

The weakness is classified as CWE-362. In practical terms, the vulnerability sits in Microsoft Windows Search and involves an unspecified flaw that lets an attacker bypass MOTW protections. MOTW is the mechanism Windows uses to mark files that originated from the internet or other untrusted sources so that additional security checks apply when those files are opened or processed.

An attacker supplies a specially crafted malicious file. When Windows Search handles that file, the MOTW defenses can be evaded, allowing remote code execution under the context of the affected process or user. No further exploit mechanics, race-condition steps, or payload details are provided in the available facts; treat the attack surface as any path that delivers a file into Windows Search processing. Confirm the precise trigger conditions and required user interaction (if any) against the Microsoft advisory.

Am I affected? How to find it in your systems

The vulnerability affects Microsoft Windows systems that include the Windows Search component. Windows Search is present by default on most client and many server installations of Windows, so assume broad exposure until proven otherwise.

If your logging does not currently capture Windows Search or MOTW-related events, enable the relevant audit policies and forward those logs to your SIEM for retrospective hunting.

How to remediate

The primary remediation is to apply the vendor-supplied update for CVE-2023-36884 as soon as it can be tested and deployed. Follow Microsoft’s instructions exactly; the CISA required action is to apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Re-scan or re-inventory after deployment to confirm coverage.

If you can't patch immediately

If immediate patching is blocked by change windows or compatibility testing, apply compensating controls while you prepare the update.

These measures reduce risk but do not replace the vendor patch. Plan to apply the official update as soon as possible.

If your data may have been exposed

Actively exploited vulnerabilities, especially those with known ransomware use, frequently lead to data theft or encryption. If you have evidence of successful exploitation or cannot rule it out, treat the incident as a potential breach: isolate affected hosts, preserve forensic artifacts, and follow your incident-response plan. As a quick personal check, you can run a free exposure scan of your email address against known breach data sets to see whether credentials or other information have already appeared in public dumps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · Windows
WeaknessCWE-362
Added to CISA KEVJul 17, 2023
Federal patch deadlineAug 29, 2023
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities