Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows a remote code execution vulnerability due to the way that Windows Search handles objects in memory, aka "Windows Search Remote Code Execution Vulnerability".
The product does not preserve permissions or incorrectly preserves permissions when copying, restoring, or sharing objects, which can cause them to have less restrictive permissions than intended.
Link | Tags |
---|---|
http://www.securitytracker.com/id/1038866 | third party advisory vdb entry |
https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/CVE-2017-8589 | patch vendor advisory |
http://www.securityfocus.com/bid/99425 | third party advisory vdb entry |