Impact
A stack-based buffer overflow exists in Windows Installer that permits an authorized local user to gain elevated privileges. The flaw occurs when installer data is processed without proper bounds checking, enabling the attacker to overwrite critical control data on the stack.
Affected Systems
Affected are numerous Microsoft Windows operating systems: Windows 10 (Builds 1607, 1809, 21H2, 22H2), Windows 11 (23H2, 24H2, 25H2, 26H1), and Windows Server editions from 2012 up to 2025, including core configurations. Any system running these versions and executing Windows Installer components is potentially vulnerable.
Risk and Exploitability
The CVSS score of 7.8 indicates a moderate to high severity for local privilege escalation, but the EPSS score of less than 1% signals a low probability of exploitation at the moment. The vulnerability is not listed in the CISA KEV catalog, so no known widespread exploits are reported. The attack vector is local and requires the attacker to have the ability to run installer actions; once the buffer overflow is triggered, the attacker can execute arbitrary code with elevated rights.
OpenCVE Enrichment