Junglewise Threat Intelligence

CVE-2026-48571: Microsoft Windows App Installer use after free privilege escalation

CVE-2026-48571 · Severity: high · CVSS 7 · Published 2026-07-14

Technologies: Microsoft Windows 11 Version 26H1, Microsoft Windows 11 Version 24H2, Microsoft Windows 11 Version 23H2, Microsoft Windows Server 2025, Microsoft Windows 11, Microsoft Windows 11 Version 25H2. Vendors: Microsoft.

Executive brief

A security vulnerability exists in the Windows App Installer, a tool used to install and manage applications on Windows devices. An attacker who already has basic access to a computer could exploit this flaw to gain higher-level administrative privileges. This could allow them to bypass security controls, access sensitive data, or install malicious software across the system.

Technical details

A use-after-free vulnerability (CWE-416) exists in the Windows App Installer component. The flaw is triggered when the application attempts to use memory after it has been freed, which can be manipulated by a local attacker to execute arbitrary code in a higher-privileged context. Exploitation requires the attacker to have low-privileged access to the target system (PR:L) and involves high complexity (AC:H), likely due to race conditions or specific memory layout requirements. Successful exploitation results in a full loss of confidentiality, integrity, and availability. Microsoft has released security updates to address this issue across affected Windows 11 and Windows Server 2025 versions.

Affected products

  • Microsoft Windows 11 Version 23H2 10.0.22631.0 to 10.0.22631.7376
  • Microsoft Windows 11 Version 24H2 10.0.26100.0 to 10.0.26100.8875
  • Microsoft Windows 11 Version 25H2 10.0.26200.0 to 10.0.26200.8875
  • Microsoft Windows 11 Version 26H1 10.0.28000.0 to 10.0.28000.2269
  • Microsoft Windows Server 2025 10.0.26100.0 to 10.0.26100.33158

Timeline

  • 2026-07-14: disclosed
  • 2026-07-14: advisory

References

Related threats