CVE-2026-69322
massDouble-Free Privilege Elevation in Microsoft Windows Search Component
A double-free memory-corruption flaw (CWE-415) exists in the Microsoft Windows Search Component, in which the same memory allocation can be released twice, corrupting process memory. Per the CVSS vector, an authorized attacker — meaning one holding valid low-privileged credentials — can trigger the flaw over a network, and some form of user interaction is required in the attack path. Successful exploitation allows the attacker to elevate privileges beyond their assigned level, with high impact on confidentiality, integrity, and availability, yielding a CVSS 3.1 base score of 8.0 (High). Any Windows installation with the Search Component present is potentially affected; the available data does not enumerate specific affected versions or editions. There are no known public proofs of concept, the flaw is not in the CISA KEV catalog, and EPSS currently estimates only a 0.7% probability of exploitation within 30 days.
What to do: Apply Microsoft's security update for CVE-2026-69322 as soon as it is available, and prioritize authenticated, network-reachable Windows hosts such as RDS, VDI, and terminal servers where untrusted users can sign in. Until patching, restrict interactive logon rights on exposed systems to trusted accounts, since exploitation requires valid low-privileged credentials plus user interaction. Because the source data does not list affected version ranges, verify applicability against Microsoft's advisory before deploying fixes.
| Microsoft Windows Search Component | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Double free in Microsoft Windows Search Component allows an authorized attacker to elevate privileges over a network.
- Weakness
- CWE-415
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.