CVE-2025-21331
Published: 14 January 2025
Description
Windows Installer Elevation of Privilege Vulnerability
Security Summary
CVE-2025-21331 is a Windows Installer Elevation of Privilege Vulnerability affecting the Windows Installer component in Microsoft Windows systems. Published on 2025-01-14, it carries a CVSS v3.1 base score of 7.3 (AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H) and is linked to CWE-59 (Improper Link Resolution Before File Access) as well as NVD-CWE-noinfo.
The vulnerability can be exploited by a local attacker who already has low-privileged access to the system. Exploitation requires low attack complexity and user interaction, such as a user opening or interacting with a malicious installer package. Successful exploitation enables the attacker to elevate privileges, resulting in high impacts to confidentiality, integrity, and availability.
The Microsoft Security Response Center advisory at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21331 provides guidance on this vulnerability, including details on patches and mitigation strategies.
Details
- CWE(s)