Junglewise Threat Intelligence

CVE-2026-69305: Microsoft Windows Search Component use-after-free

CVE-2026-69305 · Severity: high · CVSS 7.1 · Published 2026-09-08

Technologies: Microsoft Windows. Vendors: Microsoft.

Executive brief

Microsoft Windows Search is a built-in component that indexes files and content on Windows systems to enable fast searching. A use-after-free vulnerability in this component allows an authorized attacker on the network to execute code with elevated privileges, potentially compromising the entire system. An exploit could lead to data theft, unauthorized system changes, or installation of malware with administrative rights.

Technical details

A use-after-free vulnerability exists in the Microsoft Windows Search Component, allowing an authorized attacker to trigger memory corruption by accessing freed memory. The vulnerability requires prior authentication or network access from an authorized source. Successful exploitation allows an attacker to execute arbitrary code with elevated privileges, leading to complete system compromise. Patches are available through Microsoft Security Updates; affected systems should apply the latest security patches immediately.

Affected products

  • Microsoft Windows <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References

Related threats