Executive brief
Windows Search is a built-in Windows component that indexes files and enables fast local search functionality. A flaw in type conversion logic allows an authorized local user to escalate their privileges to a higher level, potentially granting them administrative access and control over the system.
Technical details
An incorrect type conversion or cast vulnerability exists in the Microsoft Windows Search Component. The vulnerability is exploitable by an authorized local attacker with user-level privileges. The flaw allows privilege escalation on the affected system, and attack preconditions require an attacker to already have local access and valid user credentials. A patch is expected to be available through Microsoft Security Updates.
Affected products
- Microsoft Windows Search Component
Timeline
- 2026-09-08: disclosed