Windows Installer
by Microsoft
CVEs (76)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-69441 | Hig | 0.45 | 7.0 | 0.00 | Sep 8, 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Installer allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-71339 | Med | 0.44 | 6.7 | 0.00 | Sep 8, 2026 | Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally. | ||
| CVE-2021-33765 | Med | 0.40 | 6.2 | 0.01 | Jul 14, 2021 | Windows Installer Spoofing Vulnerability | ||
| CVE-2021-26413 | Med | 0.40 | 6.2 | 0.01 | Apr 13, 2021 | Windows Installer Spoofing Vulnerability | ||
| CVE-2025-29837 | Med | 0.36 | 5.5 | 0.01 | May 13, 2025 | Improper link resolution before file access ('link following') in Windows Installer allows an authorized attacker to disclose information locally. | ||
| CVE-2023-32016 | Med | 0.36 | 5.5 | 0.01 | Jun 14, 2023 | Windows Installer Information Disclosure Vulnerability | ||
| CVE-2021-40455 | Med | 0.36 | 5.5 | 0.01 | Oct 13, 2021 | Windows Installer Spoofing Vulnerability | ||
| CVE-2021-36962 | Med | 0.36 | 5.5 | 0.01 | Sep 15, 2021 | Windows Installer Information Disclosure Vulnerability | ||
| CVE-2021-36961 | Med | 0.36 | 5.5 | 0.01 | Sep 15, 2021 | Windows Installer Denial of Service Vulnerability | ||
| CVE-2021-28437 | Med | 0.36 | 5.5 | 0.01 | Apr 13, 2021 | Windows Installer Information Disclosure Vulnerability | ||
| CVE-2020-0779 | Med | 0.36 | 5.5 | 0.01 | Mar 12, 2020 | An elevation of privilege vulnerability exists in the Windows Installer when MSI packages process symbolic links, aka 'Windows Installer Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0798, CVE-2020-0814, CVE-2020-0842, CVE-2020-0843. | ||
| CVE-2008-2547 | 0.01 | — | 0.08 | Jun 4, 2008 | Stack-based buffer overflow in msiexec.exe 3.1.4000.1823 and 4.5.6001.22159 in Microsoft Windows Installer allows context-dependent attackers to execute arbitrary code via a long GUID value for the /x (aka /uninstall) option. NOTE: this issue might cross privilege boundaries if… | |||
| CVE-2026-58540 | Hig | 0.00 | 7.8 | 0.00 | Jul 14, 2026 | Improper authorization in Windows Installer allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-50490 | Hig | 0.00 | 7.0 | 0.00 | Jul 14, 2026 | Use after free in Windows Installer allows an authorized attacker to elevate privileges locally. | ||
| CVE-2015-2371 | 0.00 | — | 0.02 | Jul 14, 2015 | The Windows Installer service in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a… | |||
| CVE-2014-1814 | 0.00 | — | 0.02 | Aug 12, 2014 | The Windows Installer in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a crafted application… |
- risk 0.45cvss 7.0epss 0.00
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Installer allows an authorized attacker to elevate privileges locally.
- risk 0.44cvss 6.7epss 0.00
Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.
- risk 0.40cvss 6.2epss 0.01
Windows Installer Spoofing Vulnerability
- risk 0.40cvss 6.2epss 0.01
Windows Installer Spoofing Vulnerability
- risk 0.36cvss 5.5epss 0.01
Improper link resolution before file access ('link following') in Windows Installer allows an authorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.01
Windows Installer Information Disclosure Vulnerability
- risk 0.36cvss 5.5epss 0.01
Windows Installer Spoofing Vulnerability
- risk 0.36cvss 5.5epss 0.01
Windows Installer Information Disclosure Vulnerability
- risk 0.36cvss 5.5epss 0.01
Windows Installer Denial of Service Vulnerability
- risk 0.36cvss 5.5epss 0.01
Windows Installer Information Disclosure Vulnerability
- risk 0.36cvss 5.5epss 0.01
An elevation of privilege vulnerability exists in the Windows Installer when MSI packages process symbolic links, aka 'Windows Installer Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0798, CVE-2020-0814, CVE-2020-0842, CVE-2020-0843.
- CVE-2008-2547Jun 4, 2008risk 0.01cvss —epss 0.08
Stack-based buffer overflow in msiexec.exe 3.1.4000.1823 and 4.5.6001.22159 in Microsoft Windows Installer allows context-dependent attackers to execute arbitrary code via a long GUID value for the /x (aka /uninstall) option. NOTE: this issue might cross privilege boundaries if…
- risk 0.00cvss 7.8epss 0.00
Improper authorization in Windows Installer allows an authorized attacker to elevate privileges locally.
- risk 0.00cvss 7.0epss 0.00
Use after free in Windows Installer allows an authorized attacker to elevate privileges locally.
- CVE-2015-2371Jul 14, 2015risk 0.00cvss —epss 0.02
The Windows Installer service in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a…
- CVE-2014-1814Aug 12, 2014risk 0.00cvss —epss 0.02
The Windows Installer in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a crafted application…
Page 4 of 4