CVE-2025-50173Weak Authentication in Microsoft Multimedia Redirection Installer

Severity
7.8HIGHNVD
EPSS
0.2%
top 60.67%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 12
Latest updateSep 10

Description

Weak authentication in Windows Installer allows an authorized attacker to elevate privileges locally.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages27 packages

NVDmicrosoft/windows< 10.0.14393.8330+5
NVDmicrosoft/windows_10_1507< 10.0.10240.21100
NVDmicrosoft/windows_10_1607< 10.0.14393.8330
NVDmicrosoft/windows_10_1809< 10.0.17763.7678
NVDmicrosoft/windows_10_21h2< 10.0.19044.6216

🔴Vulnerability Details

2
CVEList
Windows Installer Elevation of Privilege Vulnerability2025-08-12
GHSA
GHSA-c5jq-762r-q8rg: Weak authentication in Windows Installer allows an authorized attacker to elevate privileges locally2025-08-12

📋Vendor Advisories

1
Microsoft
Windows Installer Elevation of Privilege Vulnerability2025-08-12

🕵️Threat Intelligence

1
Bleepingcomputer
Microsoft fixes app install issues caused by August Windows updates2025-09-10
CVE-2025-50173 — Weak Authentication in Microsoft | cvebase