CVE-2025-61973: High severity Microsoft Microsoft Store vulnerability

Published Jan 15, 2026
·
Updated

A local privilege escalation vulnerability exists during the installation of Epic Games Store via the Microsoft Store. A low-privilege user can replace a DLL file during the installation process, which may result in unintended elevation of privileges.

Affected Software

2 affected components
Microsoft Microsoft Store
Epic Games Epic Games Store

Event History

Jan 15, 2026
CVE Published
via MITRE·03:19 PM
Data Sourced
via MITRE·03:19 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:16 PM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2025-61973?

CVE-2025-61973 has a low severity level due to its specific conditions and limited impact.

2

How do I fix CVE-2025-61973?

To fix CVE-2025-61973, ensure that you have updated versions of the Epic Games Store and Microsoft Store installed that contain the necessary security patches.

3

Who is affected by CVE-2025-61973?

CVE-2025-61973 affects users of the Epic Games Store installed via the Microsoft Store, particularly low-privilege users.

4

What are the implications of CVE-2025-61973?

The implications of CVE-2025-61973 include potential unauthorized privilege escalation leading to increased access rights for attackers.

5

When was CVE-2025-61973 disclosed?

CVE-2025-61973 was disclosed in 2025, highlighting a local privilege escalation vulnerability during installation.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203