Impact
A heap‑based buffer overflow in Windows Installer permits an attacker with local access to manipulate memory during the installation process, causing the installer to execute code with elevated privileges. The vulnerability enables the attacker to gain higher rights than the legitimate user, potentially allowing the installation of software, modification of system files, or any other action that requires administrative privileges.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Microsoft Windows 11 versions 23H2, 24H2, 25H2, and 26H1; Microsoft Windows Server 2012, 2012 R2, 2016, 2019, 2022, and 2025 across all supported architectures and core installations.
Risk and Exploitability
The vulnerability carries a CVSS score of 6.7, indicating moderate severity. The EPSS score is unavailable, so the actual exploitation likelihood is presently unknown, and the vulnerability is not listed in the CISA KEV catalog. An attacker must have local or authenticated access to the target machine to trigger the overflow; there is no evidence that remote execution is feasible. If the flaw is exploited, the attacker can elevate privileges and potentially compromise the system integrity and confidentiality by installing malicious software or altering critical system settings.
OpenCVE Enrichment