Executive brief
Windows Installer, a critical system component used to install and manage software on Windows computers, contains a flaw in validating package integrity checks. An authorized attacker with local access can exploit this weakness to bypass security checks and gain elevated privileges on the system, potentially gaining full administrative control.
Technical details
The vulnerability is a privilege escalation flaw in Windows Installer caused by improper validation of integrity check values in installer packages. An authorized local attacker can craft a malicious MSI package that bypasses integrity validation, allowing arbitrary code execution with elevated privileges. The attack requires local system access and an authorized user context, but does not require user interaction beyond normal installer execution. A successful exploit grants the attacker SYSTEM-level privileges. Patches are available from Microsoft Security Response Center.
Affected products
- Microsoft Windows Installer
Timeline
- 2026-09-08: disclosed