[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248392

 
 

909

 
 

195452

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

Windows Search Remote Code Execution Vulnerability - CVE-2023-36884

ID: oval:org.secpod.oval:def:90894Date: (C)2023-07-13   (M)2024-04-25
Class: VULNERABILITYFamily: windows




Windows Search Remote Code Execution Vulnerability. In an email or instant message attack scenario, the attacker could send the targeted user a specially crafted file that is designed to exploit the remote code execution vulnerability. In any case an attacker would have no way to force a user to view attacker-controlled content. Instead, an attacker would have to convince a user to take action. For example, an attacker could entice a user to either click a link that directs the user to the attacker's site or send a malicious attachment. An attacker can plant a malicious file evading Mark of the Web (MOTW) defenses which can result in code execution on the victim system.

Platform:
Microsoft Windows 10
Microsoft Windows 11
Microsoft Windows Server 2008
Microsoft Windows Server 2008 R2
Microsoft Windows Server 2012
Microsoft Windows Server 2012 R2
Microsoft Windows Server 2016
Microsoft Windows Server 2019
Microsoft Windows Server 2022
Reference:
CVE-2023-36884
CVE    1
CVE-2023-36884
CPE    29
cpe:/a:microsoft:word:2016
cpe:/o:microsoft:windows_server_2008:r2:sp1:x64
cpe:/o:microsoft:windows_server_2008:::x64
cpe:/o:microsoft:windows_server_2008:::x86
...

© SecPod Technologies