Junglewise Threat Intelligence

CVE-2026-72929: Microsoft Windows Installer privilege escalation via integrity check bypass

CVE-2026-72929 · Severity: high · CVSS 7.8 · Published 2026-09-08

Executive brief

Windows Installer, a critical system component used to install and manage software on Windows computers, contains a flaw in validating package integrity checks. An authorized attacker with local access can exploit this weakness to bypass security checks and gain elevated privileges on the system, potentially gaining full administrative control.

Technical details

The vulnerability is a privilege escalation flaw in Windows Installer caused by improper validation of integrity check values in installer packages. An authorized local attacker can craft a malicious MSI package that bypasses integrity validation, allowing arbitrary code execution with elevated privileges. The attack requires local system access and an authorized user context, but does not require user interaction beyond normal installer execution. A successful exploit grants the attacker SYSTEM-level privileges. Patches are available from Microsoft Security Response Center.

Affected products

  • Microsoft Windows Installer

Timeline

  • 2026-09-08: disclosed

References

Related threats