ZeroHour

CVE-2026-69608

mass

Integer Overflow in Microsoft Windows Search Component Allows Local Privilege Escalation

CVSS 3.1
7.8 high
EPSS
<1%p27
Published
()
Modified
AI analysis

An integer overflow (CWE-190) in the Microsoft Windows Search Component can cause arithmetic wraparound during size or index calculations, allowing memory corruption that a local, low-privileged user can leverage to elevate privileges. Exploitation requires the attacker to already have limited local access to the target system, per the CVSS vector (AV:L, PR:L, UI:N), and involves no user interaction. A successful attacker gains elevated rights on the local host, with high impact on confidentiality, integrity, and availability, meaning full local compromise, though the flaw does not by itself enable remote code execution. Any Windows installation that ships the Search Component is potentially affected; Microsoft has not published specific affected version ranges in the available data. As of the latest data there is no public proof of concept, the issue is not in CISA's Known Exploited Vulnerabilities catalog, and EPSS estimates only a 0.3% probability of exploitation within 30 days.

What to do: Apply Microsoft's fix for this CVE as soon as it is released in the corresponding monthly security update, prioritizing shared workstations, multi-user endpoints, and servers where the Windows Search service is enabled and untrusted users can log on locally or via RDP. Until patched, consider disabling the Windows Search service on systems that do not require it and restrict local/remote interactive logon rights on vulnerable hosts. Given no public PoC and no known exploitation, this can be handled in the normal patch cycle rather than as an emergency.

Affected
Microsoft Windows (Search Component)
Estimated exposure
mass≈1 billion Windows installations (Search Component ships by default on Windows 10/11 client editions) — Microsoft has publicly reported more than 1 billion active Windows devices and the Search Component is present by default on Windows 10/11 clients (with the Search feature optional on Windows Server), so the potentially exposed installed…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Integer overflow or wraparound in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.

Weakness
CWE-190
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.