CVE-2021-41379: medium-severity vulnerability in Microsoft Windows 10 Version 1507
Windows Installer Elevation of Privilege Vulnerability
Published · Updated
Prioritize patching. It under exploitation confirmed by CISA and has a public proof of concept.
Apply updates per vendor instructions.
Windows Installer has a vulnerability that allows an attacker with limited user privileges to gain elevated administrative access on a Windows system. An attacker can exploit this by manipulating installer files or processes to run malicious code with higher privileges.
CWE-59 (Improper Link Resolution Before File Access) in Windows Installer allows privilege escalation via symbolic link or directory junction manipulation during the installation process. An attacker with local user access can redirect installer operations to execute arbitrary code with SYSTEM privileges by exploiting insecure temporary file handling.
The full analysis of this CVE is available in Portuguese →
In the same product, most dangerous first.