Impact
This vulnerability is a use‑after‑free in the Windows Installer component, identified by CWE‑416. An attacker who already has authorized access can trigger the flaw to execute arbitrary code with elevated privileges, effectively gaining administrative rights on the machine. The resulting compromise enables the attacker to install software, alter system configurations, or exfiltrate data, thereby affecting confidentiality, integrity, and availability of the affected system.
Affected Systems
Microsoft Windows 11 versions 24H2, 25H2, and 26H1, as well as Windows Server 2025 and its Server Core installation, are affected. The flaw applies to both arm64 and x64 builds of the disclosed operating system versions.
Risk and Exploitability
The CVSS score of 7 highlights a high severity level, while no EPSS score is currently available and the vulnerability is not listed in CISA’s KEV catalog, suggesting no known public exploits yet. Nevertheless, because the flaw has a local, authorized attacker prerequisite, it remains a significant risk in environments where privileged users can run installer operations. Prompt patching is strongly recommended to mitigate the local escalation risk.
OpenCVE Enrichment