Impact
The vulnerability is a stack‑based buffer overflow in the Windows Installer component. An attacker who already has local machine access can craft a malicious installation package to overflow a buffer and gain elevated privileges, allowing arbitrary code execution with higher privileges and compromising system integrity. The weakness is identified as CWE‑121.
Affected Systems
Affected systems include multiple Windows releases: Windows 10 versions 1607, 1809, 21H2, 22H2; Windows 11 versions 23H2, 24H2, 25H2, 26H1; and Windows Server versions 2012, 2012 R2, 2016, 2019, 2022, 2025 (including Core installations). Only the listed editions are impacted; other editions or service packs that differ may not be affected.
Risk and Exploitability
Risk assessment: CVSS base score 7.8 indicates high severity, but the EPSS score of less than 1% indicates a low likelihood of exploitation at present. The vulnerability is not listed in CISA KEV, suggesting no known widespread exploitation. Likely attack vector requires a local user who can run a malicious MSI or invoke the installer with a crafted payload. The impact is confined to local privilege escalation, so remote attackers without local foothold cannot exploit.
OpenCVE Enrichment