CVE Tools

CVE-2026-69585

Microsoft Windows Search Component Elevation of Privilege Vulnerability

Published: Sep 8, 2026Updated: Sep 8, 2026 Sources: CVE List NVDCWE-704

Description

Incorrect type conversion or cast in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.

In plain language

AI Act now

This Windows Search flaw lets someone who already has an account on your PC gain higher privileges. If you’re using affected Windows versions and you haven’t applied recent updates, you should act now to reduce the risk.

Executive summary

CVE-2026-69585 is a Microsoft Windows Search Component elevation-of-privilege issue (CWE-704) caused by an incorrect type conversion/cast, which can let an authorized attacker with local access raise their privileges.

If affected, business impact
Local admin privilege gainFull machine takeover riskService disruptionSensitive data access

What to do now

  1. Check your Windows version/build and compare it to the fixed versions listed below for your edition.
  2. Update Windows to the fixed version for your OS (use Windows Update or your normal patch process):
    • Windows 10: fixed in 10.0.14393.9512 (or 10.0.17763.9245, or 10.0.19044.7725, or 10.0.19045.7725)
    • Windows 11: fixed in 10.0.22631.7582 (or 10.0.26100.9445, or 10.0.26200.9445, or 10.0.28000.2954)
    • Windows Server 2012: fixed in 6.2.9200.26349
    • Windows Server 2012 R2: fixed in 6.3.9600.23397
    • Windows Server 2016: fixed in 10.0.14393.9512
    • Windows Server 2019: fixed in 10.0.17763.9245
  3. Reboot after installing the updates and confirm the build number changed to the fixed value.
  4. If patching is delayed, immediately reduce who can log on locally (limit local accounts, remove unnecessary permissions) until updates are applied.
Usually a quick update

CVSS Vector Breakdown

AV:LAC:LPR:LUI:NS:UC:HI:HA:H
Exploitability
AV:LAttack Vector
Local
AC:LAttack Complexity
Low
PR:LPrivileges Required
Low
UI:NUser Interaction
None
Scope
S:UScope
Unchanged
Impact
C:HConfidentiality
High
I:HIntegrity
High
A:HAvailability
High

Weaknesses

Affected Products

and 12 more affected products View all →

Exploitability

No known exploits, KEV entries, or remediation guidance available for this vulnerability yet.

References

3

Unlock Complete Vulnerability Intelligence

Get the full picture for CVE-2026-69585 and every CVE in our database. Create a free account — no credit card required.

Create Free Account
Plain-language analysis
Impact assessment and exploitation scenario in plain English
Attack graph visualization
Interactive attack path and kill chain mapping
Exploit details & PoC links
ExploitDB, Metasploit, GitHub PoCs with direct links
Nuclei scanner templates
Ready-to-use vulnerability scanner templates
Full remediation guide
Patch instructions, workarounds, and compliance impact
Interactive AI chat
Ask questions about this vulnerability in natural language
Related vulnerabilities
Semantically similar CVEs and attack patterns
REST API & MCP access
Integrate vulnerability data into your workflows