Impact
Integer overflow or wraparound occurs in the Microsoft Windows Search Component, allowing a local attacker with existing user privileges to gain elevated rights on the system. This flaw, classified as CWE‑190, results in local privilege escalation that could enable the attacker to execute arbitrary code at a higher privilege level, potentially compromising the entire operating system.
Affected Systems
This vulnerability affects a broad range of Microsoft operating systems. Windows 10 versions 1607 through 22H2, Windows 11 editions 23H2, 24H2, 25H2, and 26H1, and Windows Server releases 2012, 2012 R2, 2016, 2019, 2022, and 2025 (including Server Core installations) are all impacted by the Windows Search Component flaw.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity, while the EPSS score is currently unavailable and the vulnerability is not listed in the CISA KEV catalog. Because the vulnerability requires a local authorized user, the likely attack vector is inferred to be local, not remote. Exploitation would involve an integer overflow that promotes the attacker to higher privileges, potentially up to SYSTEM, thereby granting full control over the affected machine.
OpenCVE Enrichment