Netskope Threat Labs

CVE-2023-36884

ATP Sandbox Adv. HeuristicsNetskope IPS

This detection identifies exploitation attempts targeting CVE-2023-36884, which has a HIGH severity rating. Microsoft's advisory names this issue the Windows Search Remote Code Execution Vulnerability, a flaw reachable through specially crafted Microsoft Office documents that lets cyberattackers execute code in the context of the logged on user.

First seen
July 2023
Last seen
September 2026
Alert Name
Document-HTML.Exploit.CVE-2023-36884
Document-Word.Exploit.CVE-2023-36884
Email-MIME.Exploit.CVE-2023-36884
Script.Exploit.CVE-2023-36884
Shortcut.Exploit.CVE-2023-36884
Win32.Exploit.CVE-2023-36884