Junglewise Threat Intelligence

CVE-2026-69322: Microsoft Windows Search Component double free vulnerability

CVE-2026-69322 · Severity: high · CVSS 8 · Published 2026-09-08

Executive brief

Microsoft Windows Search is a core system service that indexes files and enables fast local search functionality across Windows devices. A double free memory flaw in this component allows an authenticated attacker to execute arbitrary code with elevated privileges, potentially leading to full system compromise and lateral movement within an organization.

Technical details

A double free vulnerability exists in the Microsoft Windows Search Component, where memory is incorrectly freed more than once during processing. This memory corruption flaw can be triggered by an authenticated attacker over the network to corrupt heap memory and achieve arbitrary code execution with elevated privileges. The vulnerability requires prior authentication and network reachability to the affected system. An attacker exploiting this issue could escalate privileges and gain control over the compromised system. Microsoft has released security patches to address this vulnerability.

Affected products

  • Microsoft Windows Search Component

Timeline

  • 2026-09-08: disclosed

References

Related threats