PT-2023-9006 · Microsoft · Windows Installer Service+1

Simon Zuckerbraun

·

Published

2023-12-22

·

Updated

2024-12-06

·

CVE-2024-26158

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Microsoft Windows Installer Service (affected versions not specified)
Description The issue is related to the Microsoft Windows Installer Service and involves an elevation of privilege vulnerability. This vulnerability can be exploited to allow an attacker to elevate their privileges. The vulnerability is associated with the incorrect definition of a link before accessing a file, which can lead to arbitrary registry value writes.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

LPE

Link Following

Weakness Enumeration

Related Identifiers

BDU:2024-02975
CVE-2024-26158
ZDI-24-363

Affected Products

Windows Installer Service
Windows