Junglewise Threat Intelligence

CVE-2026-50373: Microsoft Windows Search Component privilege escalation

CVE-2026-50373 · Severity: high · CVSS 7.8 · Published 2026-07-14

Technologies: Microsoft Windows 10 Version 21H2, Microsoft Windows 11 Version 24H2, Microsoft Windows Server 2022, Microsoft Windows 10 Version 1809, Microsoft Windows 10 Version 22H2, Microsoft Windows 10, Microsoft Windows Server 2019, Microsoft Windows 11. Vendors: Microsoft.

Executive brief

A security vulnerability has been identified in the Windows Search Component, a core feature of the Windows operating system used for finding files and information. An attacker who already has basic access to a computer could exploit this flaw to gain higher-level administrative permissions. This could allow them to take full control of the system, access sensitive data, or bypass existing security protections.

Technical details

A privilege escalation vulnerability exists in the Microsoft Windows Search Component due to improper access control (CWE-284). An attacker with local access and low-level user privileges can exploit this flaw to gain SYSTEM-level permissions. The attack vector is local, requiring the attacker to execute code on the target machine, but it does not require user interaction. Microsoft has released security updates to address this issue across various versions of Windows 10, Windows 11, and Windows Server.

Affected products

  • Microsoft Windows 10 Version 1809 10.0.17763.0 to 10.0.17763.9020
  • Microsoft Windows 10 Version 21H2 10.0.19044.0 to 10.0.19044.7548
  • Microsoft Windows 10 Version 22H2 10.0.19045.0 to 10.0.19045.7548
  • Microsoft Windows 11 Version 24H2 10.0.26100.0 to 10.0.26100.8875
  • Microsoft Windows Server 2019 10.0.17763.0 to 10.0.17763.9020
  • Microsoft Windows Server 2022 10.0.20348.0 to 10.0.20348.5386

Timeline

  • 2026-07-14: advisory: Initial publication by Microsoft and NVD
  • 2026-07-14: patched: Security updates released by Microsoft

References

Related threats