Impact
This vulnerability is an improper authorization flaw in Windows Installer that permits an attacker who already has local access to elevate their privileges. The weakness, identified as CWE-285, allows a non‑privileged user to gain administrative rights without any additional authentication or network exploitation.
Affected Systems
The flaw affects a range of Microsoft Windows operating systems. All Windows 10 releases from version 1607 through 22H2 are impacted, as are Windows 11 releases 24H2, 25H2 and 26H1. Additionally, Windows Server editions from 2012 through 2025, including core and standard installations, are vulnerable. The issue resides in the Windows Installer component across these releases.
Risk and Exploitability
The CVSS score of 7.8 denotes a moderate‑to‑high severity. The EPSS score of less than 1% indicates that exploitation is currently rare. The vulnerability is not listed in the CISA KEV catalog. The attack requires local user privileges; the attacker must already possess some level of local access to trigger the improper authorization check during installation or execution of MSI packages.
OpenCVE Enrichment