### [CVE-2023-36884](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-36884) ![](https://img.shields.io/static/v1?label=Product&message=Windows%2010%20Version%201507&color=blue) ![](https://img.shields.io/static/v1?label=Product&message=Windows%2010%20Version%201607&color=blue) ![](https://img.shields.io/static/v1?label=Product&message=Windows%2010%20Version%201809&color=blue) ![](https://img.shields.io/static/v1?label=Product&message=Windows%2010%20Version%2021H2&color=blue) ![](https://img.shields.io/static/v1?label=Product&message=Windows%2010%20Version%2022H2&color=blue) ![](https://img.shields.io/static/v1?label=Product&message=Windows%2011%20version%2021H2&color=blue) ![](https://img.shields.io/static/v1?label=Product&message=Windows%2011%20version%2022H2&color=blue) ![](https://img.shields.io/static/v1?label=Product&message=Windows%20Server%202008%20%20Service%20Pack%202&color=blue) ![](https://img.shields.io/static/v1?label=Product&message=Windows%20Server%202008%20R2%20Service%20Pack%201%20(Server%20Core%20installation)&color=blue) ![](https://img.shields.io/static/v1?label=Product&message=Windows%20Server%202008%20R2%20Service%20Pack%201&color=blue) ![](https://img.shields.io/static/v1?label=Product&message=Windows%20Server%202008%20Service%20Pack%202%20(Server%20Core%20installation)&color=blue) ![](https://img.shields.io/static/v1?label=Product&message=Windows%20Server%202008%20Service%20Pack%202&color=blue) ![](https://img.shields.io/static/v1?label=Product&message=Windows%20Server%202012%20(Server%20Core%20installation)&color=blue) ![](https://img.shields.io/static/v1?label=Product&message=Windows%20Server%202012%20R2%20(Server%20Core%20installation)&color=blue) ![](https://img.shields.io/static/v1?label=Product&message=Windows%20Server%202012%20R2&color=blue) ![](https://img.shields.io/static/v1?label=Product&message=Windows%20Server%202012&color=blue) ![](https://img.shields.io/static/v1?label=Product&message=Windows%20Server%202016%20(Server%20Core%20installation)&color=blue) ![](https://img.shields.io/static/v1?label=Product&message=Windows%20Server%202016&color=blue) ![](https://img.shields.io/static/v1?label=Product&message=Windows%20Server%202019%20(Server%20Core%20installation)&color=blue) ![](https://img.shields.io/static/v1?label=Product&message=Windows%20Server%202019&color=blue) ![](https://img.shields.io/static/v1?label=Product&message=Windows%20Server%202022&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=10.0.0%3C%2010.0.10240.20107%20&color=brighgreen) ![](https://img.shields.io/static/v1?label=Version&message=10.0.0%3C%2010.0.14393.6167%20&color=brighgreen) ![](https://img.shields.io/static/v1?label=Version&message=10.0.0%3C%2010.0.17763.4737%20&color=brighgreen) ![](https://img.shields.io/static/v1?label=Version&message=10.0.0%3C%2010.0.19044.3324%20&color=brighgreen) ![](https://img.shields.io/static/v1?label=Version&message=10.0.0%3C%2010.0.19045.3324%20&color=brighgreen) ![](https://img.shields.io/static/v1?label=Version&message=10.0.0%3C%2010.0.20348.1906%20&color=brighgreen) ![](https://img.shields.io/static/v1?label=Version&message=10.0.0%3C%2010.0.22000.2295%20&color=brighgreen) ![](https://img.shields.io/static/v1?label=Version&message=10.0.0%3C%2010.0.22621.2134%20&color=brighgreen) ![](https://img.shields.io/static/v1?label=Version&message=6.0.0%3C%206.0.6003.22216%20&color=brighgreen) ![](https://img.shields.io/static/v1?label=Version&message=6.0.0%3C%206.1.7601.26664%20&color=brighgreen) ![](https://img.shields.io/static/v1?label=Version&message=6.1.0%3C%206.1.7601.26664%20&color=brighgreen) ![](https://img.shields.io/static/v1?label=Version&message=6.2.0%3C%206.2.9200.24414%20&color=brighgreen) ![](https://img.shields.io/static/v1?label=Version&message=6.3.0%3C%206.3.9600.21503%20&color=brighgreen) ![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-362%3A%20Concurrent%20Execution%20using%20Shared%20Resource%20with%20Improper%20Synchronization%20('Race%20Condition')&color=brighgreen) ### Description Windows Search Remote Code Execution Vulnerability ### POC #### Reference - http://seclists.org/fulldisclosure/2023/Jul/43 #### Github - https://github.com/Maxwitat/CVE-2023-36884-Scripts-for-Intune-Remediation-SCCM-Compliance-Baseline - https://github.com/Ostorlab/KEV - https://github.com/Ostorlab/known_exploited_vulnerbilities_detectors - https://github.com/ToddMaxey/CVE-2023-36884 - https://github.com/aleff-github/my-flipper-shits - https://github.com/bkzk/cisco-email-filters - https://github.com/deepinstinct/Storm0978-RomCom-Campaign - https://github.com/delivr-to/detections - https://github.com/jakabakos/CVE-2023-36884-MS-Office-HTML-RCE - https://github.com/leoambrus/CheckersNomisec - https://github.com/nomi-sec/PoC-in-GitHub - https://github.com/or2me/CVE-2023-36884_patcher - https://github.com/raresteak/CVE-2023-36884 - https://github.com/ridsoliveira/Fix-CVE-2023-36884 - https://github.com/tarraschk/CVE-2023-36884-Checker - https://github.com/whitfieldsdad/cisa_kev - https://github.com/xaitax/cisa-catalog-known-vulnerabilities - https://github.com/zerosorai/CVE-2023-36884