Description
Improper privilege management in Windows Package Manager allows an authorized attacker to elevate privileges locally.
Published: 2026-08-11
Score: 7.3 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw in Windows Package Manager permits improper privilege management, enabling an attacker who has already gained local user access to elevate their privileges. This vulnerability can allow the attacker to gain higher authority within the system, potentially accessing sensitive data or executing arbitrary code with elevated rights. The weakness is classified as CWE-269, reflecting a failure in controlling authorization functions.

Affected Systems

Microsoft App Installer is affected. Any versions distributed by Microsoft that contain the vulnerable privilege handling logic are at risk. The description does not list exact version ranges, so all installations of the App Installer should be reviewed for updates.

Risk and Exploitability

The CVSS score of 7.3 indicates a high impact if exploited, though the EPSS score of less than 1% shows that actual exploitation likelihood is currently very low. The vulnerability is not listed in the CISA KEV catalog, suggesting no publicly known widespread exploitation yet. The attack vector is inferred to be local, requiring an authorized attacker to trigger the privilege escalation. If the flaw were exploited, the attacker could gain system level or administrative rights on the host.

Generated by OpenCVE AI on August 12, 2026 at 19:36 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Enroll the device in Windows Update and apply the latest App Installer patch from Microsoft
  • Disable the App Installer component or uninstall it until the patch is applied
  • Limit user accounts from executing the App Installer by enforcing least privilege and access controls

Generated by OpenCVE AI on August 12, 2026 at 19:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 12 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
Description Improper privilege management in Windows Package Manager allows an authorized attacker to elevate privileges locally.
Title Windows Package Manager Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft app Installer
Weaknesses CWE-269
CPEs cpe:2.3:a:microsoft:app_installer:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft app Installer
References
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft App Installer
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-31T20:08:23.919Z

Reserved: 2026-07-31T16:41:44.244Z

Link: CVE-2026-68821

cve-icon Vulnrichment

Updated: 2026-08-12T15:35:29.343Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-11T17:19:06.540

Modified: 2026-08-29T17:17:53.340

Link: CVE-2026-68821

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-12T19:45:08Z

Weaknesses
  • CWE-269

    Improper Privilege Management