Junglewise Threat Intelligence

CVE-2026-69600: Microsoft Windows Search Component use-after-free privilege escalation

CVE-2026-69600 · Severity: high · CVSS 7 · Published 2026-09-08

Technologies: Microsoft Windows. Vendors: Microsoft.

Executive brief

Windows Search is a built-in Windows feature that indexes and searches files on a system. This vulnerability allows an authorized user with local system access to gain higher privileges (escalate from a standard user account to administrator level) by exploiting a use-after-free memory flaw. Successful exploitation could allow attackers to take full control of an affected computer.

Technical details

A use-after-free vulnerability exists in the Microsoft Windows Search Component, where freed memory is accessed after deallocation. The vulnerability requires an authorized attacker with local system access to trigger the flaw. The attack vector is local only (not remotely exploitable over the network). Successful exploitation results in privilege escalation, allowing an attacker to execute code with elevated privileges on the affected system. Patches are expected to be available from Microsoft through their security update process.

Affected products

  • Microsoft Windows <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References

Related threats