PT-2025-1103 · Microsoft · Windows App Package Installer+1

Published

2025-01-14

·

Updated

2025-01-16

·

CVE-2025-21275

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Windows App Package Installer (affected versions not specified)
Description The issue is related to weaknesses in the authorization procedure of the Windows App Package Installer, allowing an attacker to elevate their privileges. This can be exploited to gain elevated access to the system, potentially up to the SYSTEM level. The exploit can be triggered by having a specially crafted file viewed in Explorer or by spreading via email attachments.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

LPE

Improper Authorization

Weakness Enumeration

Related Identifiers

BDU:2025-00358
CVE-2025-21275

Affected Products

Windows
Windows App Package Installer