CVE-2026-69600
massUse-After-Free in Microsoft Windows Search Enables Local Privilege Escalation
CVE-2026-69600 is a use-after-free vulnerability (CWE-416) in the Microsoft Windows Search component, allowing an authorized attacker to elevate privileges locally. To trigger it, an attacker must already have low-privileged access on the target machine and exploit the memory-reuse flaw in the Search component; the attack requires no user interaction, though high attack complexity makes reliable exploitation non-trivial. A successful attack yields elevation of privileges on the local host, with high impact on confidentiality, integrity, and availability of that system. All Windows editions that include the Windows Search component are potentially affected, which in practice means virtually every Windows desktop and most Windows servers, with exact affected version ranges as enumerated in Microsoft's advisory. Exploitation status: no public proof-of-concept, not listed in CISA KEV, and EPSS estimates only a 0.3% probability of exploitation within 30 days.
What to do: Install the latest Microsoft cumulative Windows update that includes the fix for CVE-2026-69600 via Windows Update, WSUS, or your patch management tool, prioritizing multi-user systems such as RDS/session hosts, shared workstations, and kiosks where local low-privilege users are untrusted. No workarounds are documented in the available data; verify the Search component is patched by confirming your build includes the latest monthly cumulative update. Monitor Microsoft's advisory for exploitation updates, though current indicators (EPSS 0.3%, no KEV entry, no public PoC) suggest low near-term risk.
| Microsoft Windows (Windows Search Component) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use after free in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.