ZDI-25-293: Microsoft Windows Installer Service Link Following Information Disclosure Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.1. The following CVEs are assigned: CVE-2025-29837.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-25-293?
The ZDI-25-293 vulnerability has a high severity level due to its potential for local privilege escalation on Windows systems.
How do I fix ZDI-25-293?
To fix ZDI-25-293, ensure your Microsoft Windows installation is updated with the latest security patches provided by Microsoft.
Who is affected by ZDI-25-293?
Users running affected versions of Microsoft Windows are at risk of the local privilege escalation vulnerability identified as ZDI-25-293.
What type of attack does ZDI-25-293 facilitate?
ZDI-25-293 facilitates local privilege escalation attacks by allowing unauthorized users to execute code with higher privileges.
What initial access is required to exploit ZDI-25-293?
An attacker must first have the ability to execute low-privileged code on the target Microsoft Windows system to exploit ZDI-25-293.