Impact
The flaw in Windows Package Manager permits improper privilege management, enabling an attacker who has already gained local user access to elevate their privileges. This vulnerability can allow the attacker to gain higher authority within the system, potentially accessing sensitive data or executing arbitrary code with elevated rights. The weakness is classified as CWE-269, reflecting a failure in controlling authorization functions.
Affected Systems
Microsoft App Installer is affected. Any versions distributed by Microsoft that contain the vulnerable privilege handling logic are at risk. The description does not list exact version ranges, so all installations of the App Installer should be reviewed for updates.
Risk and Exploitability
The CVSS score of 7.3 indicates a high impact if exploited, though the EPSS score of less than 1% shows that actual exploitation likelihood is currently very low. The vulnerability is not listed in the CISA KEV catalog, suggesting no publicly known widespread exploitation yet. The attack vector is inferred to be local, requiring an authorized attacker to trigger the privilege escalation. If the flaw were exploited, the attacker could gain system level or administrative rights on the host.
OpenCVE Enrichment