ZeroHour

CVE-2026-69585

mass

Local Privilege Escalation via Type-Cast Flaw in Microsoft Windows Search Component

CVSS 3.1
7.8 high
EPSS
<1%p31
Published
()
Modified
AI analysis

An incorrect type conversion or cast (CWE-704) in the Microsoft Windows Search Component can be triggered by an authorized local user and requires no user interaction, per the CVSS vector (AV:L/PR:L/UI:N). By causing the Search Component to mishandle data through the faulty type conversion, a low-privileged local attacker can elevate privileges on the host, with high impact on confidentiality, integrity, and availability of the local system. Any Windows installation that includes the Windows Search Component is affected; the available data does not enumerate specific Windows versions, so defenders should consult Microsoft's advisory for the authoritative affected-release list. Exploitation is not yet observed: there is no known public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS assigns a 0.4% (31st percentile) probability of exploitation within 30 days.

What to do: Apply Microsoft's security update for CVE-2026-69585 via Windows Update/WSUS as it rolls out, prioritizing multi-user workstations, RDS hosts, and other systems where untrusted local accounts can sign in; internet-facing servers without local logins are lower priority. Confirm the definitive list of affected Windows versions in Microsoft's advisory and verify patch uptake through your patch-management inventory rather than waiting for a public PoC or KEV listing.

Affected
Microsoft Windows Search Component (shipped with Windows)Specific affected Windows versions not enumerated in the available data; see Microsoft's advisory for the definitive affected-product list
Estimated exposure
masshundreds of millions of Windows installations (Windows Search is a default Windows component) — Windows Search ships by default with Windows client and server editions, which collectively run on well over a billion devices, implying hundreds of millions of potentially affected installations, though actual risk is limited to unpatched…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Incorrect type conversion or cast in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.

Weakness
CWE-704
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.