Impact
The Windows Search component contains an incorrect type conversion bug that allows a local attacker with user‑level privileges to elevate to higher privileges. The flaw originates from improper handling of type casts within the search engine, effectively bypassing security boundaries and enabling full system control. This weakness aligns with CWE-704, where a flawed conversion routine undermines confidentiality, integrity, and availability.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 23H2, 24H2, 25H2, and 26H1; and Windows Server 2012, 2012 R2, 2016, 2019, 2022, and 2025—including both full installations and Server Core instances—are affected. Any installation that includes the Windows Search service on these operating systems may be vulnerable.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity, but the EPSS score is not available, and the flaw is not listed in CISA KEV, suggesting no widespread exploitation yet. The attacker must have local, authorized access and must be able to trigger the erroneous type conversion within the Search component. Even if local users are restricted, the ability to gain full local system privileges poses a critical risk, so the vulnerability warrants prompt remediation.
OpenCVE Enrichment