Historical advisory — reviewed July 15, 2026. Microsoft released security updates addressing CVE-2023-36884 on August 8, 2023. Those patches supersede the temporary registry mitigation described when the vulnerability was first disclosed. Organizations should apply current Windows security updates and investigate evidence of exploitation rather than relying on the old workaround.
Executive summary
CVE-2023-36884 is a Microsoft Windows Search vulnerability that was exploited through malicious Office documents before a patch was available. Microsoft observed the threat actor it tracks as Storm-0978 using Ukrainian World Congress-themed lures in a June 2023 phishing campaign against defense and government organizations in Europe and North America.
The documents were used to deliver a backdoor with similarities to RomCom. Microsoft describes Storm-0978 as a Russia-based group associated with espionage-focused credential theft as well as separate ransomware and extortion activity. CISA added CVE-2023-36884 to its Known Exploited Vulnerabilities Catalog and identifies it as known to have been used in ransomware campaigns.
Microsoft released security updates on August 8, 2023. The current priority is to patch supported Windows systems, validate coverage, preserve and review evidence of suspicious document activity, and contain any confirmed post-exploitation access. Patching closes the vulnerability but does not evict an attacker who already compromised a device or account.
What happened in the original campaign
Microsoft identified a June 2023 phishing campaign that used documents themed around the Ukrainian World Congress and NATO. The activity targeted defense and government organizations, primarily in Europe and North America.
The attack chain combined social engineering with exploitation:
- A targeted recipient received a phishing message containing or linking to a malicious Office document.
- The document abused CVE-2023-36884 to evade security protections and trigger code execution through Windows and Office behavior.
- The attacker delivered a backdoor with similarities to RomCom.
- Successful access could support credential theft, persistence, follow-on espionage, or other post-compromise activity.
Microsoft tracks the actor as Storm-0978. Other security vendors have used RomCom or Void Rabisu for related activity. Attribution labels vary across vendors, so defenders should base detection and response on observable behavior rather than assuming every RomCom-like artifact belongs to the same operation.
Current patch status
When Microsoft first disclosed the campaign in July 2023, no security update was available. Microsoft recommended interim protections that included Defender for Office 365, Microsoft 365 Apps protections, an attack surface reduction rule blocking Office applications from creating child processes, and a FEATURE_BLOCK_CROSS_PROTOCOL_FILE_NAVIGATION registry setting.
That status changed on August 8, 2023. Microsoft released security updates addressing CVE-2023-36884 and stated that the patches superseded the interim mitigations. Organizations should use the Microsoft Security Update Guide entry for CVE-2023-36884 to confirm affected products and original fixed versions, then deploy the latest applicable cumulative security updates to systems still in service.
The older registry setting can affect normal application behavior. It should not be presented as the default remediation now that patches are available. If the setting remains deployed, document it, test any change, and remove it only through the organization's normal change process after patch coverage has been verified.
Response and validation steps
Patch and verify
- Deploy current Windows security updates to supported systems.
- Identify endpoints that missed updates, stopped checking in, failed installation, or remain pending restart.
- Replace or isolate unsupported Windows systems.
- Validate remediation through endpoint management and vulnerability scanning rather than relying only on deployment status.
- Retain patch and rescan evidence for audit and incident-response use.
Preserve evidence before remediation when compromise is suspected
If an endpoint shows signs of malicious document execution, preserve relevant evidence before rebuilding or making broad changes. Useful evidence may include the original email and attachment, message headers, Office and Windows event data, endpoint process trees, downloaded files, network connections, Defender alerts, and identity sign-in records.
Do not delay containment when an attacker may still have access. Coordinate evidence preservation with host isolation, account protection, and the organization's incident response plan.
Hunt for the attack chain and follow-on activity
Review telemetry for:
- Office applications launching unexpected child processes, scripts, or download utilities.
- Documents or emails using Ukrainian World Congress, NATO, defense, or geopolitical lures associated with the original campaign.
- Microsoft Defender detections for RomCom or related payloads, including
Trojan:Win32/RomCom,Trojan:Win64/RomCom, andExploit:Script/Teefey. - The Microsoft Defender for Endpoint alert Emerging threat activity group Storm-0978 detected.
- Suspicious credential access, account changes, persistence, remote execution, or lateral movement after the document was opened.
- Impacket-related activity, including SMBExec or WMIExec behavior, where it is unexpected in the environment.
A detection or log match is a lead, not automatic proof of compromise. Validate the initiating document, user context, process ancestry, network activity, and follow-on behavior.
Contain confirmed or likely compromise
When evidence supports successful execution:
- Isolate affected endpoints while preserving necessary forensic data.
- Block confirmed malicious files, domains, URLs, and sender infrastructure.
- Revoke active sessions and reset credentials exposed on the affected device.
- Review privileged and service-account use from the host.
- Hunt for the same indicators and behaviors across the environment.
- Remove persistence or rebuild affected systems using the incident response team's established process.
- Validate that containment and remediation were successful before returning systems to service.
Defense in depth
Maintain layered protections even after patching. Microsoft recommends cloud-delivered antivirus protection, EDR in block mode, Defender for Office 365 protections such as Safe Attachments and Safe Links, and applicable attack surface reduction rules. Microsoft 365 Apps version 2302 and later included protections against exploitation through Office when the campaign was disclosed.
These controls are useful for phishing and post-exploitation defense, but they do not replace current Windows security updates or an investigation when suspicious activity is present.
How CulperSec can help
CulperSec can help validate patch coverage, investigate suspicious Office and endpoint activity, and coordinate containment when the evidence indicates compromise. Learn more about Managed Detection and Response or request Incident Response support.




