Description
Double free in Microsoft Windows Search Component allows an authorized attacker to elevate privileges over a network.
Published: 2026-09-08
Score: 8 High
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Apply Patch
AI Analysis

Impact

A double free flaw in the Windows Search Component enables an authorized attacker to elevate privileges on a target machine over a network connection. The vulnerability arises when memory is freed twice, allowing memory corruption that can be exploited to gain higher process privileges. The impact is a loss of integrity for the affected system, potentially enabling an attacker to execute arbitrary code or gain full control of the machine. The weakness is classified as CWE-415, improper free of a resource.

Affected Systems

System vendors affected are Microsoft and the impacted products are Windows 11 23H2, 24H2, 25H2, and 26H1, as well as Windows Server 2022 and Windows Server 2025 (including the Server Core installation). Versions exist for both arm64 and x64 architectures where applicable.

Risk and Exploitability

The CVSS score of 8.0 indicates high severity. Because EPSS data is not available, the exploitation probability is unknown, but the flaw is in a component that is often active on networked systems. The vulnerability is not part of the CISA Known Exploited Vulnerabilities catalog. The likely attack vector is a network-based authorized user who can send crafted data to the Search service, making the overall risk high for organizations that expose or allow privileged users on the network.

Generated by OpenCVE AI on September 8, 2026 at 21:19 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Microsoft Security update for Windows 11 and Windows Server listed in the Microsoft update guide for CVE-2026-69322.
  • After installing the update, ensure that the Windows Search Service runs with the least privilege required, typically the System account, and remove any unnecessary interactive users from the service’s permissions.
  • Restrict network access to systems that require Windows Search or consider disabling the service on servers that do not need it to reduce the attack surface.

Generated by OpenCVE AI on September 8, 2026 at 21:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 24 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_26h1:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_26h1:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2022:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:x64:*

Thu, 10 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft windows 11 23h2
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2025 (server Core Installation)
Vendors & Products Microsoft windows 11 23h2
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2025 (server Core Installation)

Thu, 10 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Double free in Microsoft Windows Search Component allows an authorized attacker to elevate privileges over a network.
Title Microsoft Windows Search Component Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft windows 11 23h2
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2022
Microsoft windows Server 2025
Weaknesses CWE-415
CPEs cpe:2.3:o:microsoft:windows_11_23H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_23H2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_24H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_25H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_26H1:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2022:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft windows 11 23h2
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2022
Microsoft windows Server 2025
References
Metrics cvssV3_1

{'score': 8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Windows 11 23h2 Windows 11 23h2 Windows 11 24h2 Windows 11 24h2 Windows 11 25h2 Windows 11 25h2 Windows 11 26h1 Windows 11 26h1 Windows Server 2022 Windows Server 2025 Windows Server 2025 (server Core Installation)
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-25T21:35:02.987Z

Reserved: 2026-08-03T20:49:42.867Z

Link: CVE-2026-69322

cve-icon Vulnrichment

Updated: 2026-09-10T14:44:36.555Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T18:18:49.757

Modified: 2026-09-24T15:12:19.550

Link: CVE-2026-69322

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T21:02:05Z

Weaknesses