About that Windows Installer 'make me admin' security hole. Here's how it's exploited
ID: 21719b4a-fe32-5565-aa8a-747266ca3bd8
STIX ID: report--21719b4a-fe32-5565-aa8a-747266ca3bd8
Feed Name: The Register (Security)
Threat Score
Microsoft patched CVE-2024-38014, a Windows Installer privilege-escalation flaw disclosed by SEC Consult that lets a low-privileged user hijack an MSI 'repair' process to obtain SYSTEM-level command execution; SEC Consult published technical details and an msiscan tool to detect vulnerable installers, and Microsoft indicated the flaw has been exploited in the wild—organisations should scan and patch promptly.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
