Executive brief
Windows Search is a built-in component that indexes files and content on a computer to enable fast searches. This vulnerability allows an authorized local user to read sensitive information from system memory that they should not have access to, potentially exposing passwords, encryption keys, or other confidential data.
Technical details
An out-of-bounds read vulnerability exists in the Microsoft Windows Search Component, where insufficient bounds checking allows an authenticated local attacker to access memory regions beyond the intended allocation. The vulnerability requires local access and valid user credentials. An attacker can leverage this flaw to disclose sensitive information stored in process memory. The issue has been addressed by Microsoft with a security patch.
Affected products
- Microsoft Windows Search Component <UNKNOWN>
Timeline
- 2026-09-08: disclosed