CVE-2026-69911
massUse-After-Free Local Privilege Elevation in Microsoft Windows Search Component
CVE-2026-69911 is a use-after-free memory corruption flaw (CWE-416) in the Microsoft Windows Search component. It can be triggered by an authorized attacker who already has low-privileged access on the local system, and although the attack is rated high in complexity, it requires no user interaction. A successful exploit lets the attacker elevate privileges on the local machine, with high impact on confidentiality, integrity, and availability. Any Windows system with the Windows Search component is potentially affected; the supplied data does not specify which Windows releases, so defenders should consult Microsoft's advisory for the affected version ranges. Exploitation status is currently quiet: the flaw is not in CISA's KEV, no public proof-of-concept is known, and EPSS assigns only a 0.3% probability of exploitation within 30 days.
What to do: Apply the Windows security update that remediates CVE-2026-69911 as soon as it is available via Windows Update or Microsoft's advisory, prioritizing systems where untrusted users can sign in locally (e.g., workstations, RDP-enabled hosts). No public exploit or workaround is documented, so interim risk can be reduced by limiting local and remote sign-in rights to trusted low-privileged accounts. Verify the fix by confirming the installed cumulative update matches the version listed in Microsoft's advisory for your Windows release.
| Microsoft Windows (Windows Search component) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use after free in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.