SMB: Microsoft Windows Search Information Disclosure

This signature detects attempts to exploit a known vulnerability in the Search component of Microsoft Windows. Successful exploitation results in the disclosure of information which could be used to further compromise the user's system.

Extended Description

Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allow an attacker to obtain information to further compromise the user's system when Windows Search fails to handle objects in memory, aka "Windows Search Information Disclosure Vulnerability".

Affected Products

Microsoft windows_server_2016

References

BugTraq: 98826

CVE: CVE-2017-8544

Short Name
SMB:MS-WIN-SEARCH-ID
Severity
Minor
Recommended
True
Recommended Action
Drop
Category
SMB
Keywords
CVE-2017-8544 Disclosure Information Microsoft Search Windows bid:98826
Release Date
09/12/2017
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3590
False Positive
Unknown
Vendors

Microsoft

CVSS Score

2.1

Found a potential security threat?