ZeroHour

CVE-2026-69911

mass

Use-After-Free Local Privilege Elevation in Microsoft Windows Search Component

CVSS 3.1
7.0 high
EPSS
<1%p21
Published
()
Modified
AI analysis

CVE-2026-69911 is a use-after-free memory corruption flaw (CWE-416) in the Microsoft Windows Search component. It can be triggered by an authorized attacker who already has low-privileged access on the local system, and although the attack is rated high in complexity, it requires no user interaction. A successful exploit lets the attacker elevate privileges on the local machine, with high impact on confidentiality, integrity, and availability. Any Windows system with the Windows Search component is potentially affected; the supplied data does not specify which Windows releases, so defenders should consult Microsoft's advisory for the affected version ranges. Exploitation status is currently quiet: the flaw is not in CISA's KEV, no public proof-of-concept is known, and EPSS assigns only a 0.3% probability of exploitation within 30 days.

What to do: Apply the Windows security update that remediates CVE-2026-69911 as soon as it is available via Windows Update or Microsoft's advisory, prioritizing systems where untrusted users can sign in locally (e.g., workstations, RDP-enabled hosts). No public exploit or workaround is documented, so interim risk can be reduced by limiting local and remote sign-in rights to trusted low-privileged accounts. Verify the fix by confirming the installed cumulative update matches the version listed in Microsoft's advisory for your Windows release.

Affected
Microsoft Windows (Windows Search component)
Estimated exposure
masshundreds of millions of Windows endpoints (Search is a default OS component; Windows installed base exceeds 1 billion devices) — Windows runs on over a billion devices worldwide and the Windows Search component ships by default on standard desktop and server installs, so the potential install base is in the hundreds of millions, though only locally authenticated…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.

Weakness
CWE-416
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.