CVE-2026-68896
massLocal privilege escalation via absolute path traversal in Microsoft Windows Search
CVE-2026-68896 is an absolute path traversal flaw (CWE-36) in the Microsoft Windows Search component, rated 7.8 (High) on the CVSS 3.1 scale. An attacker who already holds valid low-privileged credentials on a target machine can trigger it by causing the Search component to process an attacker-controlled absolute path, which resolves outside the intended directory and elevates the attacker's privileges locally. Successful exploitation yields local privilege escalation with high impact on confidentiality, integrity, and availability; it does not by itself provide remote access or a foothold. Exposure is broad in install terms because the Windows Search component ships with Windows client and server editions, but practical risk concentrates on systems where untrusted or multiple local accounts exist, and the specific affected builds are not enumerated in the available data. As of this analysis there is no known exploitation in the wild, no public proof-of-concept, and a low EPSS score of 0.4% (29th percentile); the flaw is not on the CISA KEV catalog.
What to do: Apply Microsoft's security update for this CVE through Windows Update/WSUS as soon as it is available, checking Microsoft's advisory for the exact affected builds and KBs since none are listed in the source data. Prioritize patching multi-user and shared-access endpoints such as RDS hosts, jump servers, and shared workstations, where a local privilege escalation yields the most value to an attacker. Because exploitation requires an authorized local account, enforce least-privilege local access and standard endpoint patch cadence; no workaround is indicated in the available data.
| Microsoft Windows (Windows Search component) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Absolute path traversal in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.
- Weakness
- CWE-36
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.