CVE-2026-69608
massInteger Overflow in Microsoft Windows Search Component Allows Local Privilege Escalation
An integer overflow (CWE-190) in the Microsoft Windows Search Component can cause arithmetic wraparound during size or index calculations, allowing memory corruption that a local, low-privileged user can leverage to elevate privileges. Exploitation requires the attacker to already have limited local access to the target system, per the CVSS vector (AV:L, PR:L, UI:N), and involves no user interaction. A successful attacker gains elevated rights on the local host, with high impact on confidentiality, integrity, and availability, meaning full local compromise, though the flaw does not by itself enable remote code execution. Any Windows installation that ships the Search Component is potentially affected; Microsoft has not published specific affected version ranges in the available data. As of the latest data there is no public proof of concept, the issue is not in CISA's Known Exploited Vulnerabilities catalog, and EPSS estimates only a 0.3% probability of exploitation within 30 days.
What to do: Apply Microsoft's fix for this CVE as soon as it is released in the corresponding monthly security update, prioritizing shared workstations, multi-user endpoints, and servers where the Windows Search service is enabled and untrusted users can log on locally or via RDP. Until patched, consider disabling the Windows Search service on systems that do not require it and restrict local/remote interactive logon rights on vulnerable hosts. Given no public PoC and no known exploitation, this can be handled in the normal patch cycle rather than as an emergency.
| Microsoft Windows (Search Component) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Integer overflow or wraparound in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.
- Weakness
- CWE-190
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.