Elevation of Privilege Vulnerability in Microsoft Windows Search Component
CVE-2026-27909
7.8HIGH
Key Information:
- Vendor
Microsoft
- Vendor
- CVE Published:
- 14 April 2026
What is CVE-2026-27909?
The Windows Search Component in Microsoft has a vulnerability that permits an authorized attacker to exploit a use-after-free condition, potentially leading to local privilege escalation. This flaw poses significant risks as it enables attackers to gain unauthorized access to higher privileged access levels within the system, thereby compromising the security of the affected devices. Users are urged to apply the latest patches to mitigate this risk and enhance their overall system security.
Affected Version(s)
Windows 10 Version 1607 32-bit Systems 10.0.14393.0 < 10.0.14393.9060
Windows 10 Version 1809 32-bit Systems 10.0.17763.0 < 10.0.17763.8644
Windows 10 Version 21H2 32-bit Systems 10.0.19044.0 < 10.0.19044.7184