Impact
A double free flaw in the Windows Search Component enables an authorized attacker to elevate privileges on a target machine over a network connection. The vulnerability arises when memory is freed twice, allowing memory corruption that can be exploited to gain higher process privileges. The impact is a loss of integrity for the affected system, potentially enabling an attacker to execute arbitrary code or gain full control of the machine. The weakness is classified as CWE-415, improper free of a resource.
Affected Systems
System vendors affected are Microsoft and the impacted products are Windows 11 23H2, 24H2, 25H2, and 26H1, as well as Windows Server 2022 and Windows Server 2025 (including the Server Core installation). Versions exist for both arm64 and x64 architectures where applicable.
Risk and Exploitability
The CVSS score of 8.0 indicates high severity. Because EPSS data is not available, the exploitation probability is unknown, but the flaw is in a component that is often active on networked systems. The vulnerability is not part of the CISA Known Exploited Vulnerabilities catalog. The likely attack vector is a network-based authorized user who can send crafted data to the Search service, making the overall risk high for organizations that expose or allow privileged users on the network.
OpenCVE Enrichment