Abstract illustration of connected devices separated by a protected security boundary.
Microsoft Windows Search Component Elevation of Privilege Vulnerability, tracked as CVE-2026-69322, is an Important Windows security issue affecting supported Windows 11 and Windows Server releases. Microsoft describes the flaw as a double-free vulnerability in the Windows Search Component that allows an authorized attacker to elevate privileges over a network.

The most consequential detail is the potential outcome: Microsoft’s advisory states that an attacker who successfully exploited the vulnerability could gain SYSTEM privileges. In practical terms, that is Windows’ highest local privilege level—an unwelcome upgrade from “authorized user” to “keys to the kingdom.”

Abstract illustration of connected devices separated by a protected security boundary. CVE-2026-69322 at a glance​

  • Title: Microsoft Windows Search Component Elevation of Privilege Vulnerability
  • Severity: Important
  • CVE: CVE-2026-69322
  • CWE: CWE-415
  • Description: Double free in Microsoft Windows Search Component allows an authorized attacker to elevate privileges over a network.
  • CVSS base score: 8.0
  • CVSS temporal score: 7.0
  • CVSS vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
  • Publicly disclosed: No
  • Exploited: No
  • Exploitation assessment: Exploitation Less Likely
  • Customer action required: Yes

A double-free flaw occurs when software attempts to release the same area of memory more than once. Memory-management errors can create conditions that let an attacker manipulate program behavior. Here, Microsoft’s scoring indicates that exploitation requires low privileges and user interaction, but the potential impact spans confidentiality, integrity, and availability.

What administrators should do​

Apply the appropriate cumulative update for the installed Windows version and verify that devices have reached the corresponding fixed build. The required update varies by release and architecture; deploying a KB intended for another Windows servicing branch is not a substitute.

Windows 11 updates and fixed builds​

  • Windows 11 Version 23H2 for ARM64-based Systems
    For Windows 11 Version 23H2 for ARM64-based Systems, install KB5122880 to reach fixed build 10.0.22631.7582.
  • Windows 11 Version 23H2 for x64-based Systems
    For Windows 11 Version 23H2 for x64-based Systems, install KB5122880 to reach fixed build 10.0.22631.7582.
  • Windows 11 Version 24H2 for ARM64-based Systems
    For Windows 11 Version 24H2 for ARM64-based Systems, install KB5124008 to reach fixed build 10.0.26100.9445.
  • Windows 11 Version 24H2 for x64-based Systems
    For Windows 11 Version 24H2 for x64-based Systems, install KB5124008 to reach fixed build 10.0.26100.9445.
  • Windows 11 Version 25H2 for ARM64-based Systems
    For Windows 11 Version 25H2 for ARM64-based Systems, install KB5124008 to reach fixed build 10.0.26200.9445.
  • Windows 11 Version 25H2 for x64-based Systems
    For Windows 11 Version 25H2 for x64-based Systems, install KB5124008 to reach fixed build 10.0.26200.9445.
  • Windows 11 Version 26H1 for ARM64-based Systems
    For Windows 11 Version 26H1 for ARM64-based Systems, install KB5124012 to reach fixed build 10.0.28000.2954.
  • Windows 11 version 26H1 for x64-based Systems
    For Windows 11 version 26H1 for x64-based Systems, install KB5124012 to reach fixed build 10.0.28000.2954.

Windows Server updates and fixed builds​

  • Windows Server 2022 (Server Core installation) (x64)
    For Windows Server 2022 (Server Core installation) (x64), install KB5122882 to reach fixed build 10.0.20348.5622.
  • Windows Server 2022 (x64)
    For Windows Server 2022 (x64), install KB5122882 to reach fixed build 10.0.20348.5622.
  • Windows Server 2025 (Server Core installation) (x64)
    For Windows Server 2025 (Server Core installation) (x64), install KB5122871 to reach fixed build 10.0.26100.33438.
  • Windows Server 2025 (x64)
    For Windows Server 2025 (x64), install KB5122871 to reach fixed build 10.0.26100.33438.

Practical deployment advice​

For managed estates, treat CVE-2026-69322 as a normal but meaningful cumulative-update deployment priority. Inventory devices by Windows release, CPU architecture, and server installation type, then confirm the applicable KB and fixed build after installation. Server Core systems deserve explicit validation rather than being assumed to follow the same maintenance outcome as desktop deployments.

Microsoft’s advisory ties this vulnerability to the Windows Search Component and says successful exploitation could yield SYSTEM privileges. That combination makes patch compliance the sensible defense: the exploitability assessment may be less urgent than an actively exploited zero-day, but a vulnerability with a high-impact privilege outcome should not linger in the backlog.

 

References

  1. Official MSRC or vendor evidence api.msrc.microsoft.com
  2. Official MSRC or vendor evidence msrc.microsoft.com
  3. Official MSRC or vendor evidence api.msrc.microsoft.com