Executive brief
The Windows Search component contains a path traversal vulnerability that allows a locally authenticated user to write files to arbitrary locations on the system. An attacker with local access could exploit this to elevate their privileges and gain administrative control of the affected computer, potentially leading to complete system compromise.
Technical details
The vulnerability is an absolute path traversal flaw in the Microsoft Windows Search component that permits an authenticated local attacker to bypass path restrictions and write files to arbitrary directories. The vulnerability requires local access and valid user credentials. By crafting malicious input to the Search component, an attacker can escalate privileges from a standard user account to SYSTEM level, gaining full administrative control. A patch is expected to be available through Windows Update.
Affected products
- Microsoft Windows Search <UNKNOWN>
Timeline
- 2026-09-08: disclosed