Impact
The vulnerability is a heap-based buffer overflow in the Microsoft Windows Search Component, enabling a local attacker with authorized access to overwrite critical memory structures and elevate their privileges. This flaw is identified as CWE‑122.
Affected Systems
Affecting Microsoft products that include the Windows Search Service, the flaw is present in Windows 11 versions 24H2, 25H2, and 26H1, as well as Windows Server 2025 builds, including the Server Core edition. The vulnerability requires the presence of these specific operating system releases; older or non‑Windows platforms are not impacted.
Risk and Exploitability
With a CVSS score of 7.8, the severity is high. The EPSS score is below 1 % and the vulnerability is not listed in the CISA KEV catalog, suggesting a low likelihood of widespread exploitation. The flaw is a local privilege escalation that requires an attacker already authenticated on the target system or with local access. Based on the description, it is inferred that the attacker could trigger the heap-based buffer overflow in the Windows Search Component, but the specific conditions that lead to exploitation are not detailed in the CVE text, so the precise attack vector is inferred rather than confirmed. On systems where the attacker has valid user rights, the vulnerability could be leveraged to gain elevated privileges.
OpenCVE Enrichment