Impact
An absolute path traversal flaw in the Windows Search Component permits a local attacker to reference files outside the intended directory hierarchy, thereby gaining elevated privileges on the target machine. The vulnerability is a form of CWE‑36, where insufficient validation of file paths leads to unintended access. Attackers who can execute code or operate a local user account can exploit this flaw to achieve privilege escalation.
Affected Systems
Microsoft Windows 11 versions 23H2, 24H2, 25H2, and 26H1, as well as Windows Server 2022 and Windows Server 2025 (including Server Core installation). The issue impacts both ARM64 and x64 architectures of the affected editions.
Risk and Exploitability
The CVSS score of 7.8 indicates a medium‑to‑high severity level. With no EPSS data available, the likelihood of exploitation remains uncertain, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector, inferred from the path traversal nature of the bug, requires an authenticated local user with the ability to interact with the Windows Search service. This means that the threat is primarily to users with local access, but the impact is severe enough to warrant immediate attention. The lack of an EPSS score and KEV listing mitigates some risk, yet the elevated privilege outcome justifies prompt remediation.
OpenCVE Enrichment