Impact
The vulnerability stems from incorrect authorization checks in the Windows Installer service, enabling an attacker with local installation privileges to execute administrative code and gain full control of the affected system. This flaw allows a user who can install MSI packages or run installer scripts to elevate privileges to the machine’s highest level. The weakness is identified as CWE-863.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, 22H2 and Windows 11 versions 23H2, 24H2, 25H2, 26H1, together with Windows Server releases 2012, 2012 R2, 2016, 2019, 2022 and 2025 (including Server Core installations) are impacted.
Risk and Exploitability
With a CVSS score of 7.8, the issue is classified as high severity. The EPSS score is not currently available, and the vulnerability is not listed in the CISA KEV catalog, suggesting limited prior exploitation data. Attackers need only local privileges and the ability to run or deploy MSI files, making the attack straightforward on systems where user accounts are granted installer rights. As no mitigation is required beyond applying the vendor fix, the timeline for patching is critical to prevent privilege escalation.
OpenCVE Enrichment