Impact
An improper access control flaw in Microsoft Windows Search allows a local attacker who already has some system access to raise their privileges. The weakness, identified as CWE‑284, indicates that authenticated users can gain unauthorized access to operations normally restricted to higher privileged users, enabling them to perform actions normally limited to administrators.
Affected Systems
Affected products include Microsoft Windows 10 versions 1809, 21H2, and 22H2; Microsoft Windows 11 versions 24H2, 25H2, and 26H1; and Windows Server releases 2019, 2022, and 2025, both standard and Server Core installations.
Risk and Exploitability
The CVSS base score is 7.8, reflecting a medium to high severity for local privilege escalation. The EPSS score is less than 1 %, indicating a low probability of current exploitation and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the attack vector is local and requires an authorized user to access the system.
OpenCVE Enrichment