← back
CVE-2024-38014

Windows Installer Elevation of Privilege Vulnerability

CVSS 7.8 HIGHEPSS 6.1%● KEVCWE-269
In short

Windows Installer can be tricked into running commands with system administrator privileges when a regular user manipulates specific installer files. This allows attackers to gain complete control over the computer.

Technical detail

CWE-269 (Improper Access Control) vulnerability in Windows Installer allows local privilege escalation when an unprivileged user can control or influence installer configuration or package contents. The attack vector requires local file system access and manipulation of installer components prior to execution, resulting in arbitrary code execution with SYSTEM privileges.

Summary generated and translated by AI from the official description.
Windows Installer Elevation of Privilege Vulnerability
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →