CVE-2021-26415: Microsoft Windows Installer Service Untrusted File Path Arbitrary File Write Vulnerability
This vulnerability allows local attackers to write data to arbitrary files on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the Windows Installer service. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of an administrator.
Other sources
Windows Installer Elevation of Privilege Vulnerability
— Microsoft
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2021-26415?
CVE-2021-26415 is rated as a critical vulnerability due to its potential to allow local attackers to write data to arbitrary files.
How do I fix CVE-2021-26415?
To fix CVE-2021-26415, apply the latest security updates from Microsoft for your affected Windows version.
What are the affected products for CVE-2021-26415?
CVE-2021-26415 affects multiple versions of Microsoft Windows, including Windows 7, Windows 10, and various Windows Server editions.
Can CVE-2021-26415 be exploited remotely?
CVE-2021-26415 requires local access to the system to exploit, meaning it cannot be exploited remotely without prior access.
Is there a patch available for CVE-2021-26415?
Yes, Microsoft has released patches for CVE-2021-26415 that need to be installed on affected systems.