ZeroHour

CVE-2026-77894

mass

Race condition in Windows Installer enables local privilege escalation

CVSS 3.1
7.0 high
EPSS
<1%p5
Published
()
Modified
AI analysis

Windows Installer contains a race condition (CWE-362) caused by improper synchronization when concurrent operations access a shared resource, with related use-after-free behavior (CWE-416). An attacker who already has authorized, low-privileged access to a machine can trigger the flaw by racing the Installer's activity, such as during an install or repair, and winning the timing window to corrupt shared state. Successful exploitation elevates the attacker's privileges locally (high impact on confidentiality, integrity, and availability), though the attack requires local access and has high attack complexity. Any system running a vulnerable version of Windows Installer is affected, but the available data does not specify exact affected Windows or Installer version ranges. There is no public proof-of-concept, no CISA KEV listing, and no known in-the-wild exploitation; EPSS estimates only a 0.2% chance of exploitation in the next 30 days.

What to do: Monitor Microsoft's security advisory for CVE-2026-77894 and apply the Windows Installer/OS security update through your normal Windows patch cycle once Microsoft publishes the definitive affected-version list, since this dataset does not include version ranges. Because exploitation requires an already-authorized local user or process, prioritize patching shared workstations, terminal servers, and VDI hosts where low-privilege or untrusted users can execute code. In the meantime, no specific workaround is available, so standard local privilege escalation hardening (limiting untrusted local code execution) reduces risk.

Affected
Microsoft Windows Installer (OS component bundled with Windows)
Estimated exposure
masson the order of 1 billion+ Windows devices (Windows Installer ships with every Windows client and server) — Windows Installer is a default operating system component present on essentially all Windows installations, and Microsoft has publicly reported over a billion active Windows devices, so the plausible affected population is effectively the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Installer allows an authorized attacker to elevate privileges locally.

Weakness
CWE-362, CWE-416
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.