CVE-2024-38014
Microsoft Windows Installer Improper Privilege Management Vulnerability
CVSS
7.8
High
EPSS
6.3%
p93
KEV
YES
Sep 10, 2024
Exploit Today
78
0-100
Published: Sep 10, 2024 · Last modified: Aug 10, 2026 · CWE-269
Product
Microsoft / Windows
Vulnerability
Microsoft Windows Installer Improper Privilege Management Vulnerability
Added to KEV
Sep 10, 2024
Remediate by
Oct 1, 2024
Known ransomware use
No
Summary description
Microsoft Windows Installer contains an improper privilege management vulnerability that could allow an attacker to gain SYSTEM privileges.
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Notes
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38014; https://nvd.nist.gov/vuln/detail/CVE-2024-38014
Windows Installer Elevation of Privilege Vulnerability