CVE-2025-50173
7.8Microsoft · Windows Installer
A weak authentication flaw in the Windows Installer service allows an attacker with local access to perform an elevation of privilege attack on affected systems.
Executive summary
A high-severity local privilege escalation vulnerability in the Windows Installer service exposes multiple versions of Windows 10 and related components to unauthorized administrative control.
Vulnerability
This vulnerability is categorized as weak authentication (CWE-1390) within the Windows Installer service. It requires an attacker to already possess low-level local access to the system to successfully trigger the escalation of privileges.
Business impact
The ability for a low-privileged user to escalate to administrative status poses a significant threat to organizational security. Successful exploitation allows an attacker to gain full control over the compromised system, facilitating data theft, the deployment of malicious software, or further lateral movement within the network. With a CVSS score of 7.8, this vulnerability represents a high risk that warrants prioritized remediation in enterprise environments.
Remediation
Immediate Action: Administrators must apply the security updates provided by Microsoft in the official update guide to address the authentication flaw.
Proactive Monitoring: Security teams should monitor system logs for unusual process creation events or unauthorized attempts to access sensitive Windows Installer directories.
Compensating Controls: Ensure that the principle of least privilege is strictly enforced for all local user accounts to limit the potential starting point for an attacker.
Exploitation status
Public Exploit Available: No (exploit_available: unknown)
Analyst recommendation
Given the potential for full system compromise, organizations should prioritize patching affected Windows 10 endpoints and the Multimedia Redirection Installer immediately. Verify that all systems have received the latest security updates to eliminate this elevation of privilege risk. Failure to address this vulnerability could grant attackers persistent, high-level access to your critical infrastructure.
More Microsoft CVEs
Sources
- Windows Installer Elevation of Privilege Vulnerability Vendor advisory