Executive brief
Windows Search is a system component that indexes and retrieves files and data on Windows computers. An integer overflow vulnerability in this component allows an authorized user with local access to escalate their privileges to system level, potentially compromising the entire computer. This could be used to bypass security controls, install malware, or access sensitive data.
Technical details
The vulnerability is an integer overflow or wraparound condition in the Microsoft Windows Search Component. It requires an authenticated attacker with local access to the system. By exploiting this integer overflow, the attacker can escalate privileges from a standard user account to SYSTEM level. This is a local privilege escalation attack, not remotely exploitable. Microsoft has released a security patch to address this issue.
Affected products
- Microsoft Windows
Timeline
- 2026-09-08: disclosed