CVE-2025-50173

7.8

Microsoft · Windows Installer

A weak authentication flaw in the Windows Installer service allows an attacker with local access to perform an elevation of privilege attack on affected systems.

Executive summary

A high-severity local privilege escalation vulnerability in the Windows Installer service exposes multiple versions of Windows 10 and related components to unauthorized administrative control.

Vulnerability

This vulnerability is categorized as weak authentication (CWE-1390) within the Windows Installer service. It requires an attacker to already possess low-level local access to the system to successfully trigger the escalation of privileges.

Business impact

The ability for a low-privileged user to escalate to administrative status poses a significant threat to organizational security. Successful exploitation allows an attacker to gain full control over the compromised system, facilitating data theft, the deployment of malicious software, or further lateral movement within the network. With a CVSS score of 7.8, this vulnerability represents a high risk that warrants prioritized remediation in enterprise environments.

Remediation

Immediate Action: Administrators must apply the security updates provided by Microsoft in the official update guide to address the authentication flaw.

Proactive Monitoring: Security teams should monitor system logs for unusual process creation events or unauthorized attempts to access sensitive Windows Installer directories.

Compensating Controls: Ensure that the principle of least privilege is strictly enforced for all local user accounts to limit the potential starting point for an attacker.

Exploitation status

Public Exploit Available: No (exploit_available: unknown)

Analyst recommendation

Given the potential for full system compromise, organizations should prioritize patching affected Windows 10 endpoints and the Multimedia Redirection Installer immediately. Verify that all systems have received the latest security updates to eliminate this elevation of privilege risk. Failure to address this vulnerability could grant attackers persistent, high-level access to your critical infrastructure.

More Microsoft CVEs

Sources