Windows Search Indexer get_RootURL Race Condition Privilege Escalation Exploit

A race condition exists in Windows Search Indexer, when the put_RootURL function wrote a user-controlled data in the memory of CSearchRoot+0x14.AT the same time, the get_RootURL function read the data located in the memory of CSearchRoot+0x14.



The vulnerability was caused by the access to a shared variable between two different methods of the same instance .
Exploit Platform
Exploit Type
Product Name