Impact
The vulnerability is a use‑after‑free flaw in the Windows Search component that allows an attacker who already has local user access to elevate privileges on the affected system. The flaw is a classic memory‑safety error and is identified as CWE‑416. If exploited, the attacker could gain higher privileges, potentially taking full control of the machine and accessing or modifying data with elevated rights.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, 22H2; Microsoft Windows 11 versions 23H2, 24H2, 25H2, and 26H1; Microsoft Windows Server 2012, 2012 R2, 2016, 2019, 2022, and 2025, including Server Core installations where applicable.
Risk and Exploitability
The CVSS score of 7.0 classifies this condition as a high‑severity local privilege escalation. No EPSS score is provided, indicating the exploitation probability is currently unknown, and the issue is not listed in the CISA KEV catalog. The likely attack vector requires an authorized local user; an attacker must already have logged on with a user account and then trigger the use‑after‑free during a Windows Search operation. Because the vulnerability resides in core OS functionality, a successful exploitation grants broad access to the system.
OpenCVE Enrichment