Impact
A heap‑based buffer overflow exists within the Windows Installer component, which can be triggered by an authorized user to gain higher privileges on the same machine. This flaw is a classic example of a memory corruption vulnerability, identified as CWE‑122, and enables the victim to elevate their access level and potentially execute arbitrary code with system rights.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Microsoft Windows 11 versions 23H2, 24H2, 25H2, and 26H1; Windows Server 2012, 2012 R2, 2016, 2019, 2022, and 2025, including all Server Core installations.
Risk and Exploitability
The CVSS score of 7.8 reflects a high impact for local privilege escalation. The EPSS score is <1%, indicating a very low exploitation probability, and the flaw is not listed in CISA’s KEV catalog, suggesting no publicly known exploits yet. However, since an attacker only needs authorized access to run an MSI or invoke the installer, the larger threat lies in compromised user accounts or malicious software distributed as installer packages. Organizations should assume the vulnerability could be leveraged during routine software deployment or by malware that uses the installer path for privilege gain.
OpenCVE Enrichment