ZeroHour

CVE-2026-62694

mass

Use-after-free local privilege escalation in Microsoft Windows Installer

CVSS 3.1
7.0 high
EPSS
<1%p17
Published
()
Modified
AI analysis

CVE-2026-62694 is a use-after-free memory-safety flaw (CWE-416) in the Windows Installer service that lets an attacker who already has an authorized account on a Windows machine gain higher privileges. Triggering it requires local access, and the high attack complexity rating (AC:H) suggests the attacker must reach a specific timing or state window during installer operations to reuse freed memory in the service. Successful exploitation yields a local privilege escalation with high impact on confidentiality, integrity, and availability — effectively running code with system-level rights, since no user interaction beyond the attacker's own low-privileged session is required. All Windows editions that ship the affected Windows Installer component are potentially affected; the source data does not list specific vulnerable builds, so defenders should consult Microsoft's advisory for the affected version range. There is currently no known exploitation: no public proof-of-concept exists, the flaw is not in CISA KEV, and EPSS estimates only a 0.3% chance of exploitation within 30 days (17th percentile).

What to do: Apply Microsoft's security update for CVE-2026-62694 through your normal patch cycle, prioritizing systems where multiple or less-trusted users can run local code, such as shared workstations, RDS/VDI hosts, and developer machines; because the bug requires an already-authorized local user and involves high attack complexity, it is a lower urgency than internet-facing flaws. Limit who can initiate installer operations on sensitive systems as an interim mitigation, verify patch status via endpoint management tooling, and monitor Microsoft's advisory for the definitive affected-build list and any change in exploitation status.

Affected
Microsoft Windows Installer (msiexec, shipped with Microsoft Windows client and server editions)
Estimated exposure
mass~1 billion+ Windows devices (Windows Installer is a built-in component of every Windows client and server installation) — Windows Installer ships as a core component of all supported Windows client and server editions, and Windows runs on over a billion active devices, so essentially every Windows deployment is within the affected footprint.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Windows Installer allows an authorized attacker to elevate privileges locally.

Weakness
CWE-416
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.