Impact
A heap‑based buffer overflow in Windows Installer can be triggered by an authorized user locally, allowing the attacker to gain higher privileges on the affected machine. This flaw enables code execution with elevated rights, which may lead to system compromise, persistence, data modification or installation of malicious software. The weakness is a classic CWE‑122 memory safety error involving an unchecked length during heap allocation.
Affected Systems
The vulnerability affects Microsoft Windows 10 version 1607, 1809, 21H2, and 22H2; Windows 11 versions 23H2, 24H2, 25H2, 26H1 and 23H2/26H1; as well as Windows Server 2012, 2012 R2, 2016, 2019, 2022 and 2025 across both standard and Server Core installations.
Risk and Exploitability
With a CVSS score of 7.8 and an EPSS below 1%, the risk level is moderate, but the low exploit probability reflects that the flaw requires local authorized access. The vulnerability is not currently listed in CISA’s KEV catalog, indicating no known large‑scale exploitation. In practice, an attacker who can run or influence an MSI installation could trigger the overflow to elevate privileges, but widespread attack is unlikely at present.
OpenCVE Enrichment