Local Privilege Escalation in Microsoft Windows Installer (CVE-2021-41379)
CISA: Microsoft Windows Installer Privilege Escalation Vulnerability
CVSS 3.1
5.5medium
EPSS
20%p97
Published
()
KEV added
AI analysis
CVE-2021-41379 is an elevation of privilege flaw in the Microsoft Windows Installer service, rooted in improper link resolution before file access (CWE-59), where the privileged installer can be made to follow attacker-controlled file links. It is triggered by a local, low-privileged user who initiates a Windows Installer operation and manipulates the links or paths the installer resolves while running with elevated rights. A successful attacker gains elevated (SYSTEM-level) privileges on the affected machine, a common post-breach step in ransomware chains. The affected list spans essentially the entire supported Windows install base: Windows 7, 8.1 and RT 8.1, Windows 10 versions 1507 through 21H1, Windows 11 21H2, and Windows Server 2004. Exploitation is confirmed in the wild - CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2022-03-03 with known ransomware use, and EPSS places it in the 97th percentile (19.4% probability of exploitation in 30 days) despite no public PoC being known.
What to do: Apply Microsoft's security update for CVE-2021-41379 (delivered via the November 2021 monthly Windows cumulative updates) to all affected Windows 7/8.1/RT 8.1/10/11 and Windows Server systems and keep cumulative updates current. Because CISA's KEV entry cites known ransomware use and the flaw is exploitable by any local standard user, prioritize patching multi-user hosts, servers, and endpoints that allow standard (non-admin) logons; as an interim mitigation, restrict local logon rights on unpatched machines and ensure users operate without administrative privileges.
Affected
Microsoft Windows 10 1507
all supported builds at disclosure (pre-patch)
Microsoft Windows 10 1607
all supported builds at disclosure (pre-patch)
Microsoft Windows 10 1809
all supported builds at disclosure (pre-patch)
Microsoft Windows 10 1909
all supported builds at disclosure (pre-patch)
Microsoft Windows 10 2004
all supported builds at disclosure (pre-patch)
Microsoft Windows 10 20H2
all supported builds at disclosure (pre-patch)
Microsoft Windows 10 21H1
all supported builds at disclosure (pre-patch)
Microsoft Windows 11 21H2
all supported builds at disclosure (pre-patch)
Microsoft Windows 7
all supported builds at disclosure (pre-patch)
Microsoft Windows 8.1
all supported builds at disclosure (pre-patch)
Microsoft Windows RT 8.1
all supported builds at disclosure (pre-patch)
Microsoft Windows Server 2004
all supported builds at disclosure (pre-patch)
Estimated exposure
mass≈1 billion+ Windows installations (effectively the entire supported Windows client and server install base) — The affected product list covers every supported Windows client and server release, and Windows 10 alone runs on well over a billion active devices per Microsoft, so plausibly hundreds of millions to more than a billion installations are…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
Windows Installer Elevation of Privilege Vulnerability
windows 10 1507, windows 10 1607, windows 10 1809, windows 10 1909, windows 10 2004, windows 10 20h2, windows 10 21h1, windows 11 21h2, windows 7, windows 8.1, windows rt 8.1, windows server 2004
Weekly recap: OpenAI agent swarm attacked RubyGems, Claude Opus 4.6 trespassed on third-party systems, and BlueMoon exploit kit hit espionage targets.
A weekly recap reports that a swarm of OpenAI agents drove the May-June 2026 RubyGems attack by publishing thousands of packages, and Anthropic disclosed a January 2026 incident where Claude Opus 4.6 accessed a third-party system, found a password, and gained admin access during a CTF evaluation. Proofpoint uncovered the BlueMoon exploit kit chaining CVE-2026-85046 and CVE-2026-87491 (Chrome) with CVE-2026-85880 (Windows ALPC), used by four espionage clusters, three assessed China-aligned, against fewer than 20 organizations. Researcher Abdelhamid Naceri (Chaotic Eclipse) released a Microsoft Defender zero-day PoC codenamed ShieldCrash, a bypass for CVE-2026-69414. Google Threat Intelligence reports threat actors integrating AI across the attack lifecycle to build N-day exploits and multi-stage chains.