LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2021-41379: Microsoft Windows Installer Privilege Escalation Vulnerability

RBRecent Breaches Vulnerability Intelligence·Mar 3, 2022
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
Mar 17, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2021-41379 to its Known Exploited Vulnerabilities catalog on Mar 3, 2022, with a federal patch deadline of Mar 17, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

Microsoft Windows Installer contains an unspecified vulnerability that allows for privilege escalation.

CVE-2021-41379 is a privilege escalation vulnerability in the Microsoft Windows Installer. It allows an attacker who already has some access on a system to gain higher privileges. CISA notes that this issue has been used in ransomware activity, which makes timely response important for Windows environments.

Defenders should treat this as a local elevation-of-privilege risk on affected Windows hosts and confirm exact scope, fixed builds, and deployment guidance directly against the Microsoft advisory.

How it works

The weakness is tracked as CWE-1386 and affects the Windows Installer component. In plain terms, the Installer does not adequately protect a sensitive operation or resource, so a lower-privileged process or user can influence Installer behavior in a way that yields elevated rights.

An attacker who can already run code or interact with the Installer on the machine abuses that flaw to escalate to a higher integrity level or administrative context. Public detail on the precise trigger is limited; treat the CISA description—an unspecified privilege-escalation issue in Windows Installer—as the authoritative high-level summary and verify any deeper technical notes only in the vendor advisory. No remote unauthenticated exploit path is implied by the given facts; the primary concern is post-compromise or malicious-local escalation, including in ransomware chains.

Am I affected? How to find it in your systems

The vulnerability affects Microsoft Windows systems that include the Windows Installer. It is relevant on workstations, servers, and any image or golden build that ships the standard Installer service and related binaries.

How to remediate

Patch first. Apply the Microsoft updates that remediate CVE-2021-41379 exactly as directed in the vendor advisory and per CISA’s required action: “Apply updates per vendor instructions.”

If you can't patch immediately

Reduce risk with compensating controls until the update can be installed.

If your data may have been exposed

Actively exploited privilege-escalation flaws are commonly used after initial access to deploy ransomware or steal data. If you have unpatched systems or see suspicious elevation and encryption activity, follow your incident-response plan: isolate hosts, preserve evidence, reset credentials, and assess what data the elevated context could reach. You can also run a free exposure scan of your email addresses against known breach data to check whether associated accounts already appear in public breach corpora and to prioritize further monitoring or credential changes.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · Windows
WeaknessCWE-1386
Added to CISA KEVMar 3, 2022
Federal patch deadlineMar 17, 2022
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities