CVE-2026-20816

7.8

Microsoft · Windows

A time-of-check time-of-use race condition in the Windows Installer component allows an authenticated local attacker to escalate privileges to a higher level.

Executive summary

A race condition vulnerability in the Microsoft Windows Installer allows local attackers to achieve unauthorized privilege escalation.

Vulnerability

This vulnerability is a time-of-check time-of-use (TOCTOU) race condition within the Windows Installer. It requires the attacker to have local authenticated access to the system to manipulate the installation process and trigger the flaw.

Business impact

Successful exploitation of this vulnerability allows a low privileged user to gain elevated permissions on the target system. This poses a significant risk to data confidentiality, integrity, and availability, as the attacker could potentially gain full control over the host. With a CVSS score of 7.8, this is classified as a high severity issue that requires prioritized attention to prevent unauthorized administrative access.

Remediation

Immediate Action: Apply the relevant security updates provided by Microsoft in the January 2026 release cycle to address the race condition in the Windows Installer.

Proactive Monitoring: Review system logs for unusual installer activity or unexpected process execution patterns that may indicate a privilege escalation attempt.

Compensating Controls: Ensure that local user permissions are strictly limited to the principle of least privilege, reducing the surface area for unauthorized local exploitation.

Exploitation status

Public Exploit Available: No (exploit_available: false).

Analyst recommendation

Given the high severity of this vulnerability and the potential for full system compromise via local privilege escalation, organizations should prioritize the deployment of the January 2026 Windows security updates. Patching the Windows Installer is essential to closing this vector and maintaining the security posture of enterprise endpoints.

More Microsoft CVEs

Sources