PT-2025-1059 · Microsoft · Windows Installer+1

Jagotu

·

Publicado

2025-01-14

·

Atualizado

2025-01-20

·

CVE-2025-21287

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Windows Installer (affected versions not specified)
Description The issue is related to insecure privilege management in the Windows Installer component of Windows operating systems. It allows an attacker to elevate their privileges to the level of SYSTEM. This can affect the system, potentially leading to unauthorized access or control.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

LPE

Improper Privilege Management

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2025-00291
CVE-2025-21287

Produtos afetados

Windows
Windows Installer