A remote code execution vulnerability exists when Windows Search handles objects in memory, aka "Windows Search Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HMicrosoft Windows 10
OSMicrosoft160717031709Microsoft Windows 7
OSMicrosoftall versionsMicrosoft Windows 8.1
OSMicrosoftall versionsMicrosoft Windows Rt 8.1
OSMicrosoftall versionsMicrosoft Windows Server 2008
OSMicrosoftr2Microsoft Windows Server 2012
OSMicrosoftr2Microsoft Windows Server 2016
OSMicrosoft17091803
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
RCE
CWE
Related vulnerabilities
CVE-2026-33824CRITICAL9.8⚠ KEVPL ✓same product
Double free w Windows IKE Extension umożliwia zdalne wykonanie kodu
CVE-2025-59287CRITICAL9.8⚠ KEVPL ✓same product
RCE w Windows Server Update Service (WSUS) — deserializacja danych
CVE-2020-1350CRITICAL10.0⚠ KEVPL ✓same product
RCE w Windows DNS Server — krytyczna podatność SIGRed (CVSS 10.0)
CVE-2020-1040CRITICAL9.0⚠ KEVPL ✓same product
RCE w Hyper-V RemoteFX vGPU — błąd walidacji wejścia od gościa
CVE-2020-0646CRITICAL9.8⚠ KEVPL ✓same product
RCE w Microsoft .NET Framework — nieprawidłowa walidacja danych wejściowych