#VU9313 Buffer overflow in Windows and Windows Server - CVE-2017-11788
Published: November 14, 2017 / Updated: November 14, 2017
Windows
Windows Server
Microsoft
Description
The vulnerability allows a remote attacker to perform a denial of service attack.
The vulnerability exists due to boundary error when handling objects in memory in Windows Search. A remote unauthenticated attacker can send a specially crafted message to the Windows Search service and crash the affected system. Additionally the attacker can trigger the vulnerability through a Server Message Block (SMB) connection.