Executive brief
Windows Search is a system component that indexes and searches files on Windows computers. A missing authentication check allows a local attacker to tamper with search functionality or indexed data, potentially affecting system performance or exposing sensitive information that should be protected from unauthorized access.
Technical details
This vulnerability is a missing authentication / authorization bypass in a critical function within the Microsoft Windows Search Component. The affected code does not properly validate caller permissions before executing sensitive operations, allowing a local attacker with standard user privileges to perform unauthorized tampering. Attack vector is local only; network-based exploitation is not possible. The exact scope of tampering (data corruption, configuration changes, or other modifications) is not fully detailed in available sources. A patch from Microsoft is expected as part of their regular security update cycle.
Affected products
- Microsoft Windows Search Component
Timeline
- 2026-09-08: disclosed