ZeroHour

CVE-2026-72929

mass

Local Privilege Escalation in Microsoft Windows Installer Integrity Check

CVSS 3.1
7.8 high
EPSS
<1%p12
Published
()
Modified
AI analysis

CVE-2026-72929 is a local privilege elevation flaw caused by improper validation of the integrity check value in Windows Installer, the built-in Microsoft component that processes MSI installation packages. An attacker who already has low-level authorized access on a machine can trigger the flaw by running a crafted installation package whose integrity check value is not correctly validated, bypassing the intended integrity verification during installation. Because Windows Installer operates with elevated rights during package installation, the attacker gains higher local privileges with high impact on confidentiality, integrity, and availability, with no user interaction required beyond the local install. Any system running the affected Windows Installer component is exposed, meaning essentially all Windows installations are potentially in scope. Exploitation has not been observed or demonstrated publicly: there is no known public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS assigns only a 0.2% probability of exploitation within 30 days.

What to do: Apply Microsoft's Windows Installer security update via Windows Update, WSUS, or your patch-management system as soon as it is released, and verify installation across your Windows estate; the source data does not provide specific patched version numbers, so track the Microsoft advisory for exact targets. Prioritize hosts where untrusted or standard users can log on and run installer packages, such as shared workstations, terminal servers, and VDI. As an interim hardening step, confirm the AlwaysInstallElevated policy is not enabled for standard users, so non-administrators cannot invoke MSI installs with elevated rights.

Affected
Microsoft Windows Installer
Estimated exposure
mass≈1 billion+ Windows devices (component ships with every Windows installation) — Windows Installer is a core built-in OS component present on effectively every Windows device, and Microsoft has publicly reported well over a billion active Windows devices, though the subset running the affected versions is not stated in…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Improper validation of integrity check value in Windows Installer allows an authorized attacker to elevate privileges locally.

Weakness
CWE-354
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.