ZDI-CAN-26153: ZDI-25-293: Microsoft Windows Installer Service Link Following Information Disclosure Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.1. The following CVEs are assigned: CVE-2025-29837.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-26153?
ZDI-CAN-26153 has a CVSS rating that indicates a significant risk for privilege escalation on affected installations of Microsoft Windows.
How do I fix ZDI-CAN-26153?
To mitigate ZDI-CAN-26153, ensure that you apply the latest security patches from Microsoft for your Windows operating system.
Who is affected by ZDI-CAN-26153?
ZDI-CAN-26153 affects installations of Microsoft Windows where local attackers can escalate privileges.
What type of vulnerability is ZDI-CAN-26153?
ZDI-CAN-26153 is a privilege escalation vulnerability that allows local attackers to gain higher permissions on the system.
What must an attacker do to exploit ZDI-CAN-26153?
An attacker must have the ability to execute low-privileged code on the target system before they can exploit ZDI-CAN-26153.