Skip to main content

CVE detail

CVE-2023-36884

Windows Search Remote Code Execution Vulnerability

CVSS 7.5 · HighBuzz score 75.0KEV listed

Buzz score

Why this CVE is surfacing

Buzz score total 75.0

This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.

Buzz score components · mention 30.0 · diversity 20.0 · KEV 25.0 · OTX 0.0 · PoC 0.0
Mention score
30.0
20 evidence mentions in the snapshot
Diversity score
20.0
9 sources across 5 categories
KEV score
25.0
Known exploited vulnerability present
OTX score
0.0
0 OTX pulses
PoC score
0.0
0 repos · best confidence N/A
Best PoC traction
0
Maximum stars on a matched PoC repo

Why it matters now

Mention timeline

Total mentions
0
within the 30d window
Peak daily
0
highest bucket

Evidence

Source links by recency

Newest mentions first
20 source links · newest first
  • A Russia-aligned group that engages in both cybercrime and cyberespionage operations used a zero-click exploit chain last month that combined previously unknown and unpatched vulnerabilities in Firefox and Windows. The campaign, whose goal was to deploy the group’s RomCom backdoor on computers, targeted users from Europe and North America. The APT group, also known as […]

    newswww.csoonline.comNov 27, 2024, 6:35 PM
  • Russia-aligned APT group RomCom was behind attacks that leveraged CVE-2024-9680, a remote code execution flaw in Firefox, and CVE-2024-49039, an elevation of privilege vulnerability in Windows Task Scheduler, as zero-days earlier this year. “Chaining together two zero-day vulnerabilities armed RomCom with an exploit that requires no user interaction,” ESET researchers said. The campaign leveraging the zero-click exploit CVE-2024-9680 allowed the attackers to execute code in the restricted context of the browser and CVE-2024-49039 allowed it … More →

    newswww.helpnetsecurity.comNov 26, 2024, 10:00 AM
  • CISA adds Sophos, Oracle and Microsoft product security holes to its Known Exploited Vulnerabilities (KEV) catalog.

    newswww.securityweek.comNov 17, 2023, 12:13 PM
  • In July 2023, pro-Russian APT Storm-0978 targeted support for Ukrainian NATO admission with an exploit chain. Analysis of it reveals the new CVE-2023-36584.

    vendorunit42.paloaltonetworks.comNov 13, 2023, 11:00 AM
  • CISA has added CVE-2023-38180, a zero-day vulnerability affecting .NET and Visual Studio, to its Known Exploited Vulnerabilities Catalog.

    newswww.securityweek.comAug 10, 2023, 8:08 AM
  • Microsoft Patch Tuesday security updates for August 2023 addressed 74 vulnerabilities, including two actively exploited flaws. Microsoft Patch Tuesday security updates for August 2023 addressed 74 new vulnerabilities in multiple products including Windows and Windows Components; Edge (Chromium-Based); Exchange Server; Office and Office Components; .NET and Visual Studio; ASP.NET; Azure DevOps and HDInsights; Teams; and […]

    newssecurityaffairs.comAug 8, 2023, 10:30 PM
  • Patch Tuesday: A month after confirming active exploitation of Office code execution flaws, Microsoft has shipped patches for multiple affected products.

    newswww.securityweek.comAug 8, 2023, 7:38 PM
  • August 2023 Patch Tuesday is here; among the 76 CVE-numbered issues fixed by Microsoft this time around is a DoS vulnerability in .NET and Visual Studio (CVE-2023-38180) for which proof-of-exploit code exists. Other than the fact that a patch is available, practically no other information has been shared by the company about CVE-2023-38180. Vulnerabilities in Microsoft Office and Exchange Server There is a Microsoft Office “Defense in Depth Update” available that, according to Microsoft, stops … More →

    newswww.helpnetsecurity.comAug 8, 2023, 7:34 PM
  • 17th July – Threat Intelligence ReportCheck Point Research

    For the latest discoveries in cyber research for the week of 17th July, please download our Threat_Intelligence Bulletin TOP ATTACKS AND BREACHES Colorado State University (CSU) has been affected by ransomware gang Cl0p’s MOVEit Managed File Transfer attack. The threat actors compromised the University’s service vendors, which resulted in an unauthorized access to personal information […]

    vendorresearch.checkpoint.comJul 17, 2023, 7:06 AM
  • Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: CISO perspective on why boards don’t fully grasp cyber attack risks In this Help Net Security interview, David Christensen, CISO of PlanSource, proposes strategies to understand and acknowledge the broader organizational and strategic implications of cybersecurity risk management, strategy, and governance. How Google Cloud’s AML AI redefines the fight against money laundering In this Help Net Security interview, Anna Knizhnik, … More →

    newswww.helpnetsecurity.comJul 16, 2023, 8:30 AM
  • A new round of the weekly SecurityAffairs newsletter arrived! Every week the best security articles from Security Affairs are free for you in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press. Russia-linked APT Gamaredon starts stealing data from victims between 30 and 50 minutes after the initial […]

    newssecurityaffairs.comJul 15, 2023, 10:18 PM
  • This threat brief provides an overview of what is known about CVE-2023-36884, a Microsoft Office and Windows HTML remote code vulnerability of important severity. Unit 42 will update the threat brief with additional analysis and protections information as available.

    vendorunit42.paloaltonetworks.comJul 12, 2023, 6:45 PM
  • Microsoft says a Chinese cyberespionage group tracked as Storm-0558 has used forged authentication tokens to access government emails.

    newswww.securityweek.comJul 12, 2023, 1:27 PM
  • Microsoft warned today that an unpatched zero-day in multiple Windows and Office products was actively exploited in the wild. Microsoft disclosed an unpatched zero-day vulnerability in multiple Windows and Office products that has been actively exploited in the wild. The issue, tracked as CVE-2023-36884, was exploited by nation-state actors and cybercriminals to gain remote code execution […]

    newssecurityaffairs.comJul 12, 2023, 7:39 AM
  • For July 2023 Patch Tuesday, Microsoft has delivered 130 patches; among them are four for vulnerabilites actively exploited by attackers, but no patch for CVE-2023-36884, an Office and Windows HTML RCE vulnerability exploited in targeted attacks aimed at defense and government entities in Europe and North America. About CVE-2023-36884 “Microsoft is investigating reports of a series of remote code execution vulnerabilities impacting Windows and Office products. Microsoft is aware of targeted attacks that attempt to … More →

    newswww.helpnetsecurity.comJul 11, 2023, 7:16 PM
  • No excerpt available.

    Mitigationwww.cisa.govJul 11, 2023, 7:15 PM
  • No excerpt available.

    Exploitseclists.orgJul 11, 2023, 7:15 PM
  • No excerpt available.

    Vendor Advisorymsrc.microsoft.comJul 11, 2023, 7:15 PM
  • Patch Tuesday: Microsoft calls attention to a series of zero-day remote code execution attacks hitting its Office productivity suite.

    newswww.securityweek.comJul 11, 2023, 6:20 PM
  • We’re halfway through 2023 already and moving into our seventh Patch Tuesday of the year next week. There’s been a lot of activity with Microsoft this month which may impact updates we’ll see. But first taking a quick look back at June, we had a fairly standard set of releases with 32 CVEs fixed in Windows 11 and 36 fixed in Windows 10. Although I call out the desktops for simplicity, always keep in mind … More →

    newswww.helpnetsecurity.comJul 7, 2023, 9:07 AM

Exploit code

Public exploit repository references

Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.

0 repository references · best confidence N/A · max 0 stars
No public PoC repositories have been matched yet.

Related records

Similar CVEs

6 related CVEs with shared weakness or product evidence