CVE-2026-61925
Windows Installer Elevation of Privilege Vulnerability
Description
Incorrect authorization in Windows Installer allows an authorized attacker to elevate privileges locally.
In plain language
AI Act nowCVE-2026-61925 is a Windows Installer flaw that can let someone who already has low-level access gain full administrative control; if your business PCs or servers are using an affected Windows version, you should patch—this is serious even though it’s not an “internet worm” type issue.
CVE-2026-61925 is a local elevation of privilege in Windows Installer (CWE-863, incorrect authorization): an attacker who already has low-privilege access can trigger a permissions/validation logic error to execute code with higher administrative rights, enabling full system impact without user interaction.
What to do now
- Check which affected Windows version/build number your business devices and servers are running (including Windows Installer usage via normal installs/updates).
- If the device is on one of the affected versions, plan an immediate update to the fixed build for that exact Windows version branch.
- Apply the Microsoft update for CVE-2026-61925 using the Microsoft Update Guide instructions.
- After patching, verify the OS build number matches one of the fixed versions listed in this note and re-run your routine update checks to confirm no pending updates remain.
CVSS Vector Breakdown
AV:LAttack VectorAC:LAttack ComplexityPR:LPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
- Microsoft Patch Tuesday for August 2026 — Snort rules and prominent vulnerabilitiesen·Cisco Talos· Exploited Windows patch-tuesday
- Microsoft Patch Tuesday, August 2026 Security Update Reviewen-us·Qualys Security Blog· Exploited Windows patch-tuesday
- Microsoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-daysen-us·BleepingComputer· Exploited Windows Lazarus group
- Microsoft Patch Tuesday August 2026 - SANS ISCen·SANS Internet Storm Center· Exploited Windows zero-day
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-61925 and every CVE in our database. Create a free account — no credit card required.
Create Free Account