Executive brief
Microsoft Windows Search Component contains a vulnerability that allows an authorized attacker to read sensitive information and disclose it over a network. This could expose confidential data stored or indexed by the Windows Search service, potentially compromising user privacy and organizational security.
Technical details
A sensitive information disclosure vulnerability exists in Microsoft Windows Search Component due to improper access controls on externally-accessible files or directories. An authorized attacker with valid credentials can exploit this to read and exfiltrate sensitive data over the network. The vulnerability allows information that should be restricted to be placed in a location accessible to unauthorized parties. No user interaction is required beyond initial authentication. Patches are available through Microsoft's standard security update process.
Affected products
- Microsoft Windows Search Component
Timeline
- 2026-09-08: disclosed