Executive brief
Windows Installer is a core Windows service responsible for managing software installation and updates on computers. A race condition in the installer allows an authorized local user to exploit improper synchronization and gain elevated system privileges, potentially enabling complete system compromise.
Technical details
The vulnerability is a race condition (CWE-362) in Windows Installer caused by improper synchronization of shared resources during concurrent execution. An authenticated local attacker can exploit this timing-dependent flaw to bypass privilege checks and execute code with SYSTEM privileges. The attack requires local access and authentication on the target system. No patch information is available from the provided advisory text, though a security update is likely available from Microsoft Security Response Center.
Affected products
- Microsoft Windows Installer <UNKNOWN>
Timeline
- 2026-09-08: disclosed