PT-2025-1059 · Microsoft · Windows Installer+1

Jagotu

·

Published

2025-01-14

·

Updated

2025-01-20

·

CVE-2025-21287

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Windows Installer (affected versions not specified)
Description The issue is related to insecure privilege management in the Windows Installer component of Windows operating systems. It allows an attacker to elevate their privileges to the level of SYSTEM. This can affect the system, potentially leading to unauthorized access or control.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

LPE

Improper Privilege Management

Weakness Enumeration

Related Identifiers

BDU:2025-00291
CVE-2025-21287

Affected Products

Windows
Windows Installer