CVE-2026-62694
massUse-after-free local privilege escalation in Microsoft Windows Installer
CVE-2026-62694 is a use-after-free memory-safety flaw (CWE-416) in the Windows Installer service that lets an attacker who already has an authorized account on a Windows machine gain higher privileges. Triggering it requires local access, and the high attack complexity rating (AC:H) suggests the attacker must reach a specific timing or state window during installer operations to reuse freed memory in the service. Successful exploitation yields a local privilege escalation with high impact on confidentiality, integrity, and availability — effectively running code with system-level rights, since no user interaction beyond the attacker's own low-privileged session is required. All Windows editions that ship the affected Windows Installer component are potentially affected; the source data does not list specific vulnerable builds, so defenders should consult Microsoft's advisory for the affected version range. There is currently no known exploitation: no public proof-of-concept exists, the flaw is not in CISA KEV, and EPSS estimates only a 0.3% chance of exploitation within 30 days (17th percentile).
What to do: Apply Microsoft's security update for CVE-2026-62694 through your normal patch cycle, prioritizing systems where multiple or less-trusted users can run local code, such as shared workstations, RDS/VDI hosts, and developer machines; because the bug requires an already-authorized local user and involves high attack complexity, it is a lower urgency than internet-facing flaws. Limit who can initiate installer operations on sensitive systems as an interim mitigation, verify patch status via endpoint management tooling, and monitor Microsoft's advisory for the definitive affected-build list and any change in exploitation status.
| Microsoft Windows Installer (msiexec, shipped with Microsoft Windows client and server editions) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use after free in Windows Installer allows an authorized attacker to elevate privileges locally.
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.