Impact
Improper privilege management in Microsoft Install Service allows an authorized attacker to elevate privileges locally, gaining permissions typically reserved for system administrators. The flaw, classified as CWE‑269: Improper Privilege Escalation, resides in the service’s internal privilege assignment logic, enabling an attacker to raise their privileges without additional credentials and potentially gain full control over the affected machine.
Affected Systems
Affected systems are Windows 10 releases 1809, 21H2, and 22H2; Windows 11 releases 24H2, 25H2, and 26H1; and Windows Server 2019 (including Server Core), 2022, and 2025 (including Server Core). The vulnerability impacts the Microsoft Install Service across these platforms, regardless of architecture.
Risk and Exploitability
The CVSS score of 7.8 classifies the vulnerability as High severity. An EPSS score of 4 % indicates a moderate likelihood that exploitation will occur. The issue is not listed in CISA KEV, and no publicly disclosed exploit references are available in the CVE data. The likely attack vector is local, requiring authorized access to modify or interact with the Install Service’s privilege settings to achieve escalation.
OpenCVE Enrichment