ZeroHour

CVE-2026-69600

mass

Use-After-Free in Microsoft Windows Search Enables Local Privilege Escalation

CVSS 3.1
7.0 high
EPSS
<1%p21
Published
()
Modified
AI analysis

CVE-2026-69600 is a use-after-free vulnerability (CWE-416) in the Microsoft Windows Search component, allowing an authorized attacker to elevate privileges locally. To trigger it, an attacker must already have low-privileged access on the target machine and exploit the memory-reuse flaw in the Search component; the attack requires no user interaction, though high attack complexity makes reliable exploitation non-trivial. A successful attack yields elevation of privileges on the local host, with high impact on confidentiality, integrity, and availability of that system. All Windows editions that include the Windows Search component are potentially affected, which in practice means virtually every Windows desktop and most Windows servers, with exact affected version ranges as enumerated in Microsoft's advisory. Exploitation status: no public proof-of-concept, not listed in CISA KEV, and EPSS estimates only a 0.3% probability of exploitation within 30 days.

What to do: Install the latest Microsoft cumulative Windows update that includes the fix for CVE-2026-69600 via Windows Update, WSUS, or your patch management tool, prioritizing multi-user systems such as RDS/session hosts, shared workstations, and kiosks where local low-privilege users are untrusted. No workarounds are documented in the available data; verify the Search component is patched by confirming your build includes the latest monthly cumulative update. Monitor Microsoft's advisory for exploitation updates, though current indicators (EPSS 0.3%, no KEV entry, no public PoC) suggest low near-term risk.

Affected
Microsoft Windows (Windows Search Component)
Estimated exposure
mass≈1 billion+ Windows devices (Windows Search ships by default across the Windows installed base of roughly 1.4 billion active devices) — Windows Search is a default OS component present on essentially all Windows client machines and most servers, so the affected install base is on the order of the entire Windows fleet (~1.4 billion active devices per Microsoft's published…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.

Weakness
CWE-416
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.