Sceawere

Vulnerability Detail

CVE-2026-59135UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Microsoft Windows Search Information Disclosure

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.5
Creation Date
7h ago
Vendor
Microsoft
Product
Windows 10 Version 1607
Attack Type
CWE-1390: Weak Authentication
Vector String
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

Weak authentication in Microsoft Windows Search Component allows an authorized attacker to disclose information locally.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.5",
  "pubDate": "2026-08-11T17:18:07.980Z",
  "pubdate": "2026-08-11T17:18:07.980Z",
  "executiveSummary": "This vulnerability involves a weak authentication flaw within the Microsoft Windows Search Component, specifically enabling local information disclosure.\nThe security defect allows an authorized threat actor to extract sensitive data from the underlying operating system through improper handling of authentication mechanisms.\nThe affected product is the Microsoft Windows Search Component across supported architectures.\nThe primary risk implication is the unauthorized extraction of local information, which may expose sensitive user or system data to malicious actors.\nAttacker capabilities are strictly confined to local access vectors, requiring the adversary to possess prior authorization on the target machine.\nExploitation requirements dictate that the attacker must already be authenticated locally to interact with the vulnerable component and trigger the information disclosure vector.",
  "technicalDetails": "The vulnerability resides within the Microsoft Windows Search Component due to weak authentication enforcement during internal processing routines and local IPC (Inter-Process Communication) handlers.\nThe root cause stems from inadequate validation of security contexts and access control lists (ACLs) when handling queries or requests within the search indexing architecture.\nThe affected component is the Microsoft Windows Search Component, which processes system queries and indexes local file systems.\nThe attack flow proceeds as follows: First, an authorized local attacker establishes a session on the target system. Second, the adversary crafts a specialized query or interaction targeting the vulnerable search component interface. Third, due to the weak authentication mechanisms in place, the component fails to properly validate the caller's privilege boundaries or session constraints. Finally, the component returns requested indexed data or metadata that the user should normally be restricted from accessing, resulting in unauthorized local information disclosure.\nAuthentication requirements dictate that the attacker must be authorized on the local host to interact with the system interface.\nPrivilege requirements are minimal, as standard authorized users can typically trigger the vulnerable code path.\nNetwork exposure is non-existent, as the vulnerability is strictly local and cannot be exploited remotely.\nThe post-exploitation impact is limited to local information disclosure, potentially exposing confidential files, metadata, or system configuration details indexed by the search service."
}
CVE-2026-59135: Microsoft Windows Search Information Disclosure (MEDIUM Severity, CVSS: 5.5) - Sceawere