Impact
The flaw is an integer overflow or wraparound in the Windows Installer component that can be triggered by an authorized local user. Exploitation allows the attacker to obtain higher privileges on the system, potentially giving them control over critical system resources and the ability to install malicious software. This impact is a local privilege escalation that can compromise the confidentiality, integrity, and availability of the affected machine.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Microsoft Windows 11 versions 23H2, 24H2, 25H2, and 26H1 (including arm64 and x64 architectures); Microsoft Windows Server 2012, 2012 R2, 2016, 2019, 2022, and 2025 (both standard and Server Core installations).
Risk and Exploitability
The vulnerability has a CVSS score of 7.8, indicating a high severity. No EPSS score is currently available, and the issue is not listed in the CISA KEV catalog, suggesting that large‑scale exploitation has not yet been reported. The likely attack vector is a local adversary who can run the Windows Installer with sufficient privileges to trigger the integer overflow. With existing local credentials, exploitation is straightforward and can lead to system‑wide privilege escalation.
OpenCVE Enrichment