Impact
The flaw arises from missing authentication for a critical Windows Search Component function, letting an authorized user tamper with the component’s behavior. In practice, this could mean altering search indexes, modifying stored data, or causing a denial of service for end users. The impact is a loss of data integrity for the search feature, but it does not grant remote code execution or elevate privileges beyond what the attacker already possesses.
Affected Systems
This vulnerability affects Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2, as well as Windows 11 releases 23H2, 24H2, 25H2, and 26H1. It also applies to Windows Server editions 2012, 2012 R2, 2016, 2019, 2022, and the forthcoming 2025, across both desktop and server core installations and all supported architectures (x86, x64, arm64).
Risk and Exploitability
The CVSS score of 5.5 reflects moderate risk, and the absence of an EPSS score or KEV listing suggests no widespread exploitation has been observed. The attack vector is local, requiring the attacker to be authenticated on the compromised system; consequently, the flaw allows tampering by trusted users but does not enable broader remote or privileged exploits.
OpenCVE Enrichment