Executive brief
Windows Installer, a core component responsible for installing and managing software on Windows systems, contains a heap-based buffer overflow vulnerability. An authorized local attacker can exploit this flaw to execute code with elevated privileges, potentially gaining full control of the affected system and compromising all data and operations running on it.
Technical details
A heap-based buffer overflow exists in Windows Installer that allows a local, authenticated attacker to elevate privileges. The vulnerability requires the attacker to already have local access to the system. Exploitation results in arbitrary code execution with elevated privileges. A patch is available from Microsoft through the security update referenced in the advisory.
Affected products
- Microsoft Windows Installer
Timeline
- 2026-08-11: disclosed