ZeroHour

CVE-2024-38014

KEVmass

Local Privilege Escalation in Microsoft Windows Installer (Actively Exploited)

CISA: Microsoft Windows Installer Improper Privilege Management Vulnerability

CVSS 3.1
7.8 high
EPSS
6%p93
Published
()
KEV added
AI analysis

CVE-2024-38014 is an elevation-of-privilege flaw caused by improper privilege management (CWE-269) in the Microsoft Windows Installer component, rated 7.8 (high) with a local attack vector, low privileges required, and no user interaction. An attacker who already has limited access and can execute code on a targeted machine can trigger the vulnerable Installer behavior to gain elevated privileges, with high impact on the confidentiality, integrity, and availability of the host. The flaw affects the listed Windows 10, Windows 11, and Windows Server versions (CISA describes the affected product simply as 'Microsoft Windows', so other versions may also be impacted). It was fixed as part of Microsoft's September 2024 Patch Tuesday, which addressed 79 flaws including four actively exploited zero-days, and Microsoft's advisories plus CISA's KEV entry (added 2024-09-10) confirm it is being exploited in the wild; no public proof-of-concept is known and ransomware association is unknown. Its EPSS score of 6.3% (93rd percentile) is unusually high for a local privilege escalation, so Windows fleets should treat this as a priority patch.

What to do: Apply Microsoft's September 2024 security updates (or any later cumulative update) for the affected Windows 10, Windows 11, and Windows Server versions, prioritizing servers and multi-user systems where untrusted local code runs; because this flaw is KEV-listed and actively exploited, remediation should follow CISA's vendor-instruction requirement. Given September 2024 reporting that a servicing defect left some Windows PCs unpatched despite appearing updated, verify via Windows Update history or your patch-management tooling that the cumulative update actually installed. No workaround is specified in the available data, so patching is the primary mitigation.

Affected
Microsoft Windows 101507, 1607, 1809, 21H2, 22H2
Microsoft Windows 1121H2, 22H2, 23H2, 24H2
Microsoft Windows Server2008, 2012, 2016
Estimated exposure
mass≈1 billion+ Windows devices (Windows Installer is a core component of every affected Windows install) — Windows Installer ships with every Windows installation and Microsoft's publicly stated Windows installed base is on the order of 1.4 billion devices, so exposure before patching is effectively the entire Windows fleet across the listed…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Windows Installer Elevation of Privilege Vulnerability

CISA Known Exploited Vulnerability
Affected
Microsoft Windows
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
microsoft
Products
windows 10 1507, windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 21h2, windows 11 22h2, windows 11 23h2, windows 11 24h2, windows server 2008, windows server 2012, windows server 2016
Weakness
CWE-269
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news