Impact
Concurrent execution using a shared resource without proper synchronization leads to a race condition in the Windows Installer, allowing an authorized local attacker to elevate privileges. The weakness permits the attacker to modify MSI installation behavior, potentially granting administrative rights or executing malicious code with elevated permissions.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 23H2 through 26H1; and Windows Server releases from 2012 to 2025, including Server Core installations. All affected editions share the vulnerable Windows Installer component.
Risk and Exploitability
The CVSS score of 7 indicates moderate severity, and the EPSS score of <1% indicates a very low probability of exploitation. Based on the description, it is inferred that the vulnerability requires local authorization; therefore the likely attack vector is an authenticated local user attempting to run a malicious MSI package. The lack of a public exploit and its absence from the KEV catalog suggest limited current exploitation risk, but the capability to raise privileges remains valuable to an attacker.
OpenCVE Enrichment