Impact
The vulnerability is a use‑after‑free in the Windows Search component. This flaw is classified as CWE‑416. An authorized attacker who can trigger the use‑after‑free on a running system can elevate privileges over the network, potentially allowing further exploitation.
Affected Systems
All listed Microsoft Windows systems are impacted. This includes Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 23H2, 24H2, 25H2, and 26H1; and all Windows Server releases from Server 2012 through Server 2025, including their Server Core installations. The affected component is the built‑in Windows Search service.
Risk and Exploitability
The CVSS score of 7.1 indicates a medium severity issue; the EPSS score is not available, so the current likelihood of exploitation is unknown. The flaw is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is an authorized network attacker who can influence the Search component to trigger the use‑after‑free. If successfully exploited, the attacker can elevate privileges to the level of the search service process, which might enable broader compromise or lateral movement within the network.
OpenCVE Enrichment