CVE-2026-69305
massUse-After-Free Privilege Escalation in Microsoft Windows Search Component
CVE-2026-69305 is a use-after-free memory-safety flaw (CWE-416) in the Microsoft Windows Search Component that Microsoft has classified as an elevation-of-privilege vulnerability. To trigger it, an attacker who already holds authorized low-privileged credentials must, over a network, get a user to interact with attacker-influenced input in a way that trips the freed-memory condition; the high attack-complexity score indicates this is not trivially reproducible. A successful attacker gains elevated privileges on the target system, with high impact on confidentiality, integrity, and availability. Any Windows installation containing the Windows Search Component is in scope, although Microsoft has not published specific affected version ranges in the data available here. There is no known public proof-of-concept, the flaw is absent from CISA's Known Exploited Vulnerabilities catalog, and EPSS assigns only a 0.6% (48th percentile) probability of exploitation within 30 days, so no exploitation is currently known.
What to do: Apply the corresponding Microsoft security update as soon as it is available through Windows Update, WSUS, or Intune, and check Microsoft's advisory for the exact affected and fixed build numbers, since version ranges are not specified in this data. Because exploitation requires an authenticated low-privileged account plus user interaction, prioritize patching multi-user and internet-exposed Windows hosts where untrusted users can trigger content interaction. Until patched, restrict interactive sessions and untrusted content handling on sensitive systems where feasible.
| Microsoft Windows (Search Component) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use after free in Microsoft Windows Search Component allows an authorized attacker to elevate privileges over a network.
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.