Junglewise Threat Intelligence

CVE-2026-71339: Microsoft Windows Installer heap-based buffer overflow

CVE-2026-71339 · Severity: medium · CVSS 6.7 · Published 2026-09-08

Executive brief

Windows Installer, a core system component responsible for installing and managing software on Windows systems, contains a heap-based buffer overflow vulnerability. An authorized local attacker can exploit this flaw to elevate their privileges on the system, potentially gaining administrative control and compromising the entire machine.

Technical details

A heap-based buffer overflow exists in Windows Installer that permits privilege escalation. The vulnerability requires local access and legitimate user credentials (authorized attacker). The attack vector is local execution, and successful exploitation allows an attacker to escalate privileges to a higher privilege level. A patch is expected to be available through Microsoft Security Updates for affected Windows versions.

Affected products

  • Microsoft Windows Installer

Timeline

  • 2026-09-08: disclosed

References

Related threats