CVE-2025-21287
Published: 14 January 2025
Description
Windows Installer Elevation of Privilege Vulnerability
Security Summary
CVE-2025-21287 is a Windows Installer Elevation of Privilege Vulnerability affecting Microsoft Windows systems. Published on January 14, 2025, it carries a CVSS v3.1 base score of 7.8 (AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) and is associated with CWE-269 (Improper Privilege Management) along with NVD-CWE-noinfo.
A local attacker with low privileges can exploit this vulnerability due to its low attack complexity and lack of required user interaction. Successful exploitation allows the attacker to achieve high impacts on confidentiality, integrity, and availability, enabling privilege escalation on the affected system.
The Microsoft Security Response Center advisory at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21287 provides guidance on mitigation and patching for this vulnerability.
Details
- CWE(s)