Impact
Use after free in a component of Microsoft Windows Search allows an authorized attacker to elevate privileges locally, enabling the attacker to gain administrative or higher rights on the affected system. The flaw is identified as CWE-416, which can result in the execution of arbitrary code with the privileges of the elevated process, potentially leading to full system compromise, data modification, or persistence. The impact is limited to the user executing the attack but can extend system‑wide through elevated rights once achieved.
Affected Systems
The vulnerability affects multiple Microsoft operating systems, including Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 23H2, 24H2, 25H2, 26H1; and Windows Server releases 2012, 2012 R2, 2016, 2019, 2022, and 2025 (including core installations). All affected platforms run the Windows Search component that contains the use‑after‑free flaw and are therefore susceptible if they have not received the latest security update.
Risk and Exploitability
The CVSS score of 7 indicates moderate severity, and the EPSS score is not available, but the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a local, authenticated user who can initiate Windows Search operations, limiting the exploit to local privilege escalation. Exploitation would likely involve manipulating memory allocated to search queries to trigger the use‑after‑free condition, leading to arbitrary code execution within the elevated context. Without a patch, an attacker with local access could execute the exploit; therefore, the risk is significant for each unpatched system.
OpenCVE Enrichment