Junglewise Threat Intelligence

CVE-2026-69585: Microsoft Windows Search Component privilege escalation

CVE-2026-69585 · Severity: high · CVSS 7.8 · Published 2026-09-08

Executive brief

Windows Search is a built-in Windows component that indexes files and enables fast local search functionality. A flaw in type conversion logic allows an authorized local user to escalate their privileges to a higher level, potentially granting them administrative access and control over the system.

Technical details

An incorrect type conversion or cast vulnerability exists in the Microsoft Windows Search Component. The vulnerability is exploitable by an authorized local attacker with user-level privileges. The flaw allows privilege escalation on the affected system, and attack preconditions require an attacker to already have local access and valid user credentials. A patch is expected to be available through Microsoft Security Updates.

Affected products

  • Microsoft Windows Search Component

Timeline

  • 2026-09-08: disclosed

References

Related threats