CVE-2024-38014: Microsoft Windows Installer Improper Privilege Management Vulnerability
Microsoft Windows Installer contains an improper privilege management vulnerability that could allow an attacker to gain SYSTEM privileges.
Other sources
Windows Installer Elevation of Privilege Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.1.7601.27320Patch KB5043092 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.17763.6293Patch KB5043050 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.3.9600.22175Patch KB5043138 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.2.9200.25073Patch KB5043125 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.0.6003.22870Patch KB5043087 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.14393.7336Patch KB5043051 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.10240.20766Patch KB5043083 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26100.1742Patch KB5043080 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22631.4169Patch KB5043076 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.25398.1128Patch KB5043055 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19045.4894Patch KB5043064 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22621.4169Patch KB5043076 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19044.4894Patch KB5043064 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22000.3197Patch KB5043067 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.20348.2700Fixed in 10.0.20348.2695Patch KB5042880
Event History
Frequently Asked Questions
What is the severity of CVE-2024-38014?
CVE-2024-38014 has a high severity rating as it can allow an attacker to gain SYSTEM privileges.
How do I fix CVE-2024-38014?
To fix CVE-2024-38014, apply the latest security updates and patches provided by Microsoft for the affected versions.
Which Windows versions are affected by CVE-2024-38014?
CVE-2024-38014 affects various versions of Windows, including Windows 10, Windows 11, and Windows Server 2008 and later.
Can CVE-2024-38014 be exploited remotely?
Yes, CVE-2024-38014 can be exploited remotely, potentially allowing attackers to execute arbitrary commands with elevated privileges.
Is there a workaround for CVE-2024-38014 if I cannot update immediately?
While no formal workarounds are recommended, limiting access to the affected systems may reduce exposure to CVE-2024-38014.