CVE-2026-72929
massLocal Privilege Escalation in Microsoft Windows Installer Integrity Check
CVE-2026-72929 is a local privilege elevation flaw caused by improper validation of the integrity check value in Windows Installer, the built-in Microsoft component that processes MSI installation packages. An attacker who already has low-level authorized access on a machine can trigger the flaw by running a crafted installation package whose integrity check value is not correctly validated, bypassing the intended integrity verification during installation. Because Windows Installer operates with elevated rights during package installation, the attacker gains higher local privileges with high impact on confidentiality, integrity, and availability, with no user interaction required beyond the local install. Any system running the affected Windows Installer component is exposed, meaning essentially all Windows installations are potentially in scope. Exploitation has not been observed or demonstrated publicly: there is no known public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS assigns only a 0.2% probability of exploitation within 30 days.
What to do: Apply Microsoft's Windows Installer security update via Windows Update, WSUS, or your patch-management system as soon as it is released, and verify installation across your Windows estate; the source data does not provide specific patched version numbers, so track the Microsoft advisory for exact targets. Prioritize hosts where untrusted or standard users can log on and run installer packages, such as shared workstations, terminal servers, and VDI. As an interim hardening step, confirm the AlwaysInstallElevated policy is not enabled for standard users, so non-administrators cannot invoke MSI installs with elevated rights.
| Microsoft Windows Installer | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Improper validation of integrity check value in Windows Installer allows an authorized attacker to elevate privileges locally.
- Weakness
- CWE-354
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.