Impact
The vulnerability resides in the Windows Search Component where a missing authorization check allows an authorized user to tamper locally with the search functionality. This flaw permits modification of search configuration or data stored by the component, which can implicitly alter the integrity of system files or user data. The effect is limited to data tampering rather than remote execution or denial of service, and requires the attacker to have local access to the affected system.
Affected Systems
Affected products include a range of Windows client and server operating systems: Windows 10 versions 1607, 1809, 21H2, 22H2; Windows 11 versions 23H2, 24H2, 25H2, 26H1; as well as Windows Server versions 2012, 2012 R2, 2016, 2019, 2022, and 2025, both standard and Server Core installations.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity, and no EPSS score is available while the vulnerability is not listed in the CISA KEV catalog. The attack vector is purely local; an attacker must be authorized on the machine to exploit the missing check. Because of this limited scope, the risk is confined to insider threats or compromised accounts, and no published exploitation methods are currently known.
OpenCVE Enrichment