CISA KEV · catalog date Jul 17, 2023 · first observed Jul 19, 2026
Evidence dossier
CVE-2023-36884
Windows Search Remote Code Execution Vulnerability
Exploited in the wild (CISA KEV since Jul 17, 2023). microsoft reports CVSS 3.1 7.5. EPSS estimates 98.9% exploit likelihood as of Aug 8, 2026.
As of Aug 27, 2026
Normalized restatement
Windows Search Remote Code Execution Vulnerability
- State
- PUBLISHED
- Published
- Jul 11, 2023
- Updated
- Oct 21, 2025
- Evidence coverage
- 91%
Evidence chronology
What was known when
- Source dateSource date omittedFirst observed by CASCACISA-ADPOriginal evidence ↗
Record text: CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
- Source dateSource date omittedFirst observed by CASCACVE ProgramOriginal evidence ↗
Record text: CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
- Source dateSource date omittedFirst observed by CASCAmicrosoftOriginal evidence ↗
Record text: Windows Search Remote Code Execution Vulnerability
Inspect raw assertion
- Field
container- Value
- Windows Search Remote Code Execution Vulnerability
- Source dateFirst observed by CASCACISA KEVOriginal evidence ↗
Exploitation cataloged: Microsoft Windows Search Remote Code Execution Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- Microsoft Windows Search Remote Code Execution Vulnerability
- Source dateFirst observed by CASCAFIRST EPSSOriginal evidence ↗
EPSS score: 98.93% probability · 99.92th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.989320000000; percentile 0.999240000000
FIRST EPSS · score date Aug 8, 2026 · 99.9th percentile · first observed Aug 8, 2026
microsoft · CVSS 3.1 · first observed Jul 19, 2026 · same-version scores align in this snapshot
Evidence detail
Source limits and decisions
Why each evidence state has this value
casca-unknown-reasons-v1Eligible evidence is present for this bounded claim.
- Revision
- evidence-policy-v1.1.0
- Cutoff
- Aug 27, 2026
- Resolution
- None
Eligible evidence is present for this bounded claim.
- Revision
- evidence-policy-v1.1.0
- Cutoff
- Aug 27, 2026
- Resolution
- None
Eligible evidence is present for this bounded claim.
- Revision
- casca-direct-cvss-eligibility-v1
- Cutoff
- Aug 27, 2026
- Resolution
- None
The cited source assertion is retained while canonical product linkage remains open.
- Revision
- casca-factor-d-obligations-v1
- Cutoff
- Aug 27, 2026
- Resolution
- Resolve identity
Source comparison
Who said what
CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
Windows Search Remote Code Execution Vulnerability
Inspect raw assertion
- Field
container- Value
- Windows Search Remote Code Execution Vulnerability
Microsoft Windows Search Remote Code Execution Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- Microsoft Windows Search Remote Code Execution Vulnerability
98.93% probability · 99.92th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.989320000000; percentile 0.999240000000
Applicability
Cited product scope
Grouped from 1 configuration nodes in this exact snapshot. Visual grouping is navigational; asset exposure and root cause require cited evidence.
Identity source boundaries
- Cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z
27d65b0f-b718-4b4f-bb79-c47c68d09dfa - Cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z
955dae73-7302-438b-aee1-058d7cc5d48e
34 scope groups
Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "10.0.10240.0", "lessThan": "10.0.10240.20107", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "10.0.14393.0", "lessThan": "10.0.14393.6167", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "10.0.0", "lessThan": "10.0.17763.4737", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "10.0.17763.0", "lessThan": "10.0.17763.4737", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "10.0.19043.0", "lessThan": "10.0.19044.3324", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "10.0.19045.0", "lessThan": "10.0.19045.3324", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "10.0.0", "lessThan": "10.0.22000.2295", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "10.0.22621.0", "lessThan": "10.0.22621.2134", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "6.1.7601.0", "lessThan": "6.1.7601.26664", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "6.1.7601.0", "lessThan": "6.1.7601.26664", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "6.0.6003.0", "lessThan": "6.0.6003.22216", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "6.0.6003.0", "lessThan": "6.0.6003.22216", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "6.0.6003.0", "lessThan": "6.0.6003.22216", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "6.2.9200.0", "lessThan": "6.2.9200.24414", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "6.3.9600.0", "lessThan": "6.3.9600.21503", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "6.3.9600.0", "lessThan": "6.3.9600.21503", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "6.2.9200.0", "lessThan": "6.2.9200.24414", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "10.0.14393.0", "lessThan": "10.0.14393.6167", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "10.0.14393.0", "lessThan": "10.0.14393.6167", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "10.0.17763.0", "lessThan": "10.0.17763.4737", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "10.0.17763.0", "lessThan": "10.0.17763.4737", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "10.0.20348.0", "lessThan": "10.0.20348.1906", "versionType": "custom"}]product-9851bd571b8ab08bca589cd73710badfef557d036f0fb7707f694f1c9f597cb4Linked exactInspect raw assertion
cpe:2.3:o:microsoft:windows_10_1507:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 0
- Logic
- OR
- Version bounds
- through excluding 10.0.10240.20107
- Match ID
0b6341ee-9f08-41f4-aac9-69fcfd57aa29
product-740fec3e9838b5eabe76ebe27e4d0d7a4cb2e0ef7e13923300d3d0b51e3fce1cLinked exactInspect raw assertions
cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x86:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 2
- Logic
- OR
- Version bounds
- through excluding 10.0.14393.6167
- Match ID
e8dfa790-add0-48be-814e-e116eef26f43
cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x64:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 1
- Logic
- OR
- Version bounds
- through excluding 10.0.14393.6167
- Match ID
def8cf5e-b09e-4735-aec5-43a6359e84ec
product-a3084138383423221f61594e86f5b295e5e254acd7ae5284f45e0877a084db43Linked exactInspect raw assertions
cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x64:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 4
- Logic
- OR
- Version bounds
- through excluding 10.0.17763.4737
- Match ID
4ed72372-ba24-406b-aeab-a889fbcdaf59
cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:arm64:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 3
- Logic
- OR
- Version bounds
- through excluding 10.0.17763.4737
- Match ID
268b7ab1-1d81-4b21-943e-54024111daa7
cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x86:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 5
- Logic
- OR
- Version bounds
- through excluding 10.0.17763.4737
- Match ID
30943c07-5aef-482d-9cba-885cdf7b3f3f
Affected-product evidence
Accepted scope and product mapping
12 canonical links · 1 source-reported links
vendor-01299a5a765aea70faa05f2d06e0c26a5d498fd34553e868d89e8a43b31864db · product-02e254d111ce604757a15650ef469f4f8365d6247da82ce3ac2695c3cfc7dc5f
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
bdfa79ae-6a5c-4dbf-8133-9b845d3dc36avendor-01299a5a765aea70faa05f2d06e0c26a5d498fd34553e868d89e8a43b31864db · product-217b1ab3d25f361a639824f86753d418b35aa2a816ee370bb71b5d1dd883d87a
- Source class
- Nvd cpe vulnerable target
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
376cd21e-53b9-4c70-a774-64116f70205ea597b624-79d9-455a-adf2-e42dac5467cavendor-01299a5a765aea70faa05f2d06e0c26a5d498fd34553e868d89e8a43b31864db · product-25a2932c0bbcb648f7e391c8b9d34c734e5085444c03c1c206b9d4c4baa80b25
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
bffd6794-9603-4de3-8abb-69a7f143dc17vendor-01299a5a765aea70faa05f2d06e0c26a5d498fd34553e868d89e8a43b31864db · product-5a80416e92fed0cddbb3d4f3840218b448dee11159824ad25a0353da566963fe
- Source class
- Nvd cpe vulnerable target
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
4f46df5c-ad27-4a98-a9da-3de28386c52a6afb4ad1-8f15-4402-afd7-e9150f1c99favendor-01299a5a765aea70faa05f2d06e0c26a5d498fd34553e868d89e8a43b31864db · product-740fec3e9838b5eabe76ebe27e4d0d7a4cb2e0ef7e13923300d3d0b51e3fce1c
- Source class
- Nvd cpe vulnerable target
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
80b087f2-39a3-4143-b516-706811ec65fb94a065e8-ef84-4a83-8f06-a93b3d2ba1f2vendor-01299a5a765aea70faa05f2d06e0c26a5d498fd34553e868d89e8a43b31864db · product-7fe28b5b5b17e017d9554204df059dd619746ffb5c80da87bcbfb1c52720d2f4
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
850af4c4-c016-4dd4-8b80-41fb82e8b784vendor-01299a5a765aea70faa05f2d06e0c26a5d498fd34553e868d89e8a43b31864db · product-9851bd571b8ab08bca589cd73710badfef557d036f0fb7707f694f1c9f597cb4
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
c12331d9-2009-4f4d-8872-6e6c2889f410vendor-01299a5a765aea70faa05f2d06e0c26a5d498fd34553e868d89e8a43b31864db · product-a3084138383423221f61594e86f5b295e5e254acd7ae5284f45e0877a084db43
- Source class
- Nvd cpe vulnerable target
- Assertions
- 3
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
5ddb924f-5dc1-47a9-8ae5-cab041974367c0853bcb-227f-4f0f-8373-789d643e527de73b20d7-fd52-419a-b562-4f1b7a629203vendor-01299a5a765aea70faa05f2d06e0c26a5d498fd34553e868d89e8a43b31864db · product-a6295b9daad3ca57ce70751badba5b7fe99229c8a562cc7400e8cfef3daccaee
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
2d26f19d-f227-43e9-b219-11a3ce7428a4vendor-01299a5a765aea70faa05f2d06e0c26a5d498fd34553e868d89e8a43b31864db · product-d196d31962e613955a91e33e795c22dcfa7bf25173abebaca616a6350cce9ce1
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
6aab2e24-f88b-433c-b70d-efa0af5c833dvendor-01299a5a765aea70faa05f2d06e0c26a5d498fd34553e868d89e8a43b31864db · product-ec10c9f400f23fdf118887f60fe116ffde4adb76dcf118cdd3a7556fd033da3b
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
c5df7eb2-8219-4671-8286-45d314dd4eafvendor-01299a5a765aea70faa05f2d06e0c26a5d498fd34553e868d89e8a43b31864db · product-f8c509b6ec25f2a4338a23556be321da5a7c3e8da9f1a4c52f7f15dd0e9a0d2a
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
ea5380f6-629a-491e-9660-94d1f4c39a86Canonical linkage remains open; the cited source assertion is retained below.
Vendor specified only by source · Product specified only by source
- Source class
- Direct cve affected
- Assertions
- 22
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
03db1f37-8c51-460d-82b2-9ab52e20dd2a0f27a5b0-549b-4267-b957-ee75a960eca715b7593a-90f0-4d75-956c-4f311bd1617e171ebbc4-8898-463b-b9c6-6a8aef0680651eee6334-8de1-4ce8-9da3-64c1b498555d26e4d80c-242f-4c4f-be3c-7f7d3e18b29d2c76794f-dcfa-4921-a387-d8ebac5c6f0231f86785-a026-4011-ad0d-fb6d7a13b3ad435b6f37-10d9-4e20-b5e9-5cb62732313c61d797d9-8af4-4342-8597-b7497a61dc73693cfe98-a104-43b7-988d-cb6859f65803707215ef-7365-495a-b633-626265a21baf754e481d-310a-4c7f-b18c-c1030bfa56bf863632ac-97b9-4048-a488-fb0e70b3e2ada050eb2f-6d96-4406-9304-bfd7db9fe8d8afe6f404-7359-4016-a4e7-4c357ab7d5d7b2836258-aeab-4c10-817b-4d16bcf593e8bedfdff7-49cd-4eae-95f6-e791234e766cd595abb6-81e6-428f-a519-e2f6b6ef59b2e2e00859-ce44-40df-b7c5-e1b76722bf66e300b381-e456-4a39-8cfd-00d9443f888bfe2918a8-c538-401f-9ca0-84131a3bdbe3Assessments
CVSS by origin
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:HCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:HCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H/E:F/RL:O/RC:CDirect CVE/CNA normalized decisions
microsoft
CVSS 3.1 · Primary · Original assertion · rank 1
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C- Validation
- Valid match
- Recomputed
- 7.5
- Decision reason
- Evidence supported
- Policy
- casca-direct-cvss-eligibility-v1
Assessments are retained side by side under closed precedence. Cascade never averages CVSS.
Evidence boundaries
- KEV membership is authoritative for the catalog, not proof of exposure in any environment.
- EPSS is a dated model probability and not an individual-environment prediction.
- Affected or fixed status applies only to the exact cited product and version scope; remaining scope stays source-scoped.
- NVD-carried upstream facts remain derivative; independent corroboration requires a separately authored source.
- Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
- NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
- Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.
- OSV aggregation and OSV-converted NVD material are not independent corroboration.
- Red Hat facts are vendor assertions for the exact supplied products.
- Nonmembership and not-yet-observed states are not proof of safety.