← Vulnerability feed

Vulnerability record · CVE-2023-36884 · published 11 July 2023

CVE-2023-36884: Microsoft Windows Search race condition allows remote code execution

Microsoft · Windows 10 1507

CVE-2023-36884 is a race condition (CWE-362) in Microsoft Windows Search that permits remote code execution. It affects a broad set of Windows 10, Windows 11 and Windows Server releases. Because it is listed in CISA KEV with known ransomware use and a very high EPSS score, it is a high-priority target for both initial access and follow-on activity.

7.5 CVSS 3.1 High CISA KEV since 17 Jul 2023 Known ransomware use EPSS 99% · top 0.1% CWE-362 · Race condition
7.5CVSS 3.1 base score
99%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
12Affected product versions listed by NVD
4References
10 Aug 2026Last modified by NVD

Description

Windows Search Remote Code Execution Vulnerability

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: medium.

critical priorityIt is in CISA KEV with known ransomware use and has an EPSS probability above 0.98, so exploitation is both observed and highly likely.

What it is

CVE-2023-36884 is a race condition (CWE-362) in Microsoft Windows Search that permits remote code execution. It affects a broad set of Windows 10, Windows 11 and Windows Server releases. Because it is listed in CISA KEV with known ransomware use and a very high EPSS score, it is a high-priority target for both initial access and follow-on activity.

Impact

An attacker who wins the race can execute code on the victim host, giving them the ability to run arbitrary commands in the context of the affected process. In observed campaigns this has been chained with ransomware deployment.

Attack surface

The flaw is network-reachable (AV:N) with no privileges required (PR:N), but exploitation requires user interaction (UI:R), meaning a victim must open or interact with a crafted file or link. No authentication is needed to reach the vulnerable component.

Exploitation

CVE-2023-36884 is in CISA KEV (added 2023-07-17) with known ransomware campaign use, and EPSS reports a 30-day probability of 0.98932 (99.9th percentile), indicating active exploitation in the wild.

What to do

  • Apply the Microsoft security update for CVE-2023-36884 as soon as possible across all affected Windows 10, Windows 11 and Windows Server versions.
  • Follow CISA KEV required action: apply vendor mitigations or discontinue use of the product if mitigations are unavailable.
  • Block or restrict execution of untrusted Office and document files that can trigger the Windows Search parsing path, and enforce Mark-of-the-Web.
  • Segment and harden endpoints that run Windows Search, and restrict outbound network access to reduce post-exploitation and ransomware staging.
  • Monitor for and remove any attacker persistence or tooling associated with known ransomware groups using this CVE.

Detection

  • Hunt for suspicious child processes spawned by searchindexer.exe or Windows Search-related processes, especially those launching scripting or command interpreters.
  • Alert on Office or document files that spawn unexpected processes or make network connections shortly after being opened.
  • Review endpoint telemetry for race-condition exploitation patterns such as repeated rapid file or search operations followed by code execution.
  • Correlate KEV and EPSS indicators with EDR alerts for Windows Search and monitor for ransomware precursor behaviors on affected hosts.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2023-36884 to the Known Exploited Vulnerabilities catalog on 17 July 2023 as "Microsoft Windows Search Remote Code Execution Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 29 August 2023.

Ransomware crews whose documented playbooks reference this CVE: