Executive brief
Microsoft Windows Installer contains a privilege escalation vulnerability caused by improper link resolution before file access (link following). An attacker with local access can exploit this to gain elevated system privileges.
Affected products
- Microsoft Windows 10 up to (excluding) 10.0.19043.1348
- Microsoft Windows 11 up to (excluding) 10.0.22000.318
- Microsoft Windows Server 2022 up to (excluding) 10.0.20348.350
- Microsoft Windows 7 SP1
- Microsoft Windows 8.1
- Microsoft Windows Server 2019 up to (excluding) 10.0.17763.2300
Timeline
- 2021-11-09: disclosed: Initial Microsoft advisory publication date (implied by CVE year and patch cycle)
- 2022-03-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2022-03-03: exploited: Confirmed exploited in the wild per CISA KEV catalog.