Impact
A stack‑based buffer overflow in Windows Installer allows an authorized local attacker to gain higher privileges. Using this flaw, a malicious installer can cause the installer process to write beyond its stack bounds, leading to an elevation of privilege that may enable the attacker to execute arbitrary code with elevated rights. The weakness is a classic stack overflow (CWE‑121).
Affected Systems
Affected systems include Microsoft Windows 10 from version 1607 through 22H2, Windows 11 from 23H2 to 26H1, and Windows Server editions from 2012 through 2025, including all Server Core installations.
Risk and Exploitability
With a CVSS score of 7.8, the vulnerability presents medium‑to‑high severity locally. The EPSS score is not available and the issue is not listed in the CISA KEV catalog, suggesting the exploitation risk is not immediately high but still significant for systems that run untrusted installers. The likely attack vector is a local user running a malicious or compromised installer; therefore, exploitation requires authorized local access or the ability to deliver a crafted installation package. If achieved, the attacker could gain administrative privileges, enabling full control over the affected machine.
OpenCVE Enrichment