Impact
The vulnerability is a heap-based buffer overflow in the Windows Installer component. An attacker with local authorized access could exploit this flaw to execute arbitrary code with elevated privileges, effectively bypassing security restrictions of the user account. The weakness corresponds to CWE-122.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 23H2, 24H2, 25H2, and 26H1; and all Microsoft Windows Server releases from 2012 through 2025 are impacted. The issue manifests in the Windows Installer service across these operating systems.
Risk and Exploitability
The CVSS score of 7.8 classifies this as high severity, but the EPSS score of less than 1% indicates a very low probability of exploitation. The vulnerability is not listed in CISA's KEV catalog. Attacking this flaw requires local administrative privileges; an adversary must already have legitimate access to the machine to influence the Windows Installer component, making it a local privilege escalation vector.
OpenCVE Enrichment