CVE-2025-50173
published 2025-08-12CVE-2025-50173: Weak authentication in Windows Installer allows an authorized attacker to elevate privileges locally.
PriorityP346high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.49%
38.7th percentile
Weak authentication in Windows Installer allows an authorized attacker to elevate privileges locally.
Affected
49 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | multimedia_redirection_installer | >= 1.0.2 < 1.0.2507.21006 | 1.0.2507.21006 |
| microsoft | windows_10_1507 | < 10.0.10240.21100 | 10.0.10240.21100 |
| microsoft | windows_10_1607 | < 10.0.14393.8330 | 10.0.14393.8330 |
| microsoft | windows_10_1809 | < 10.0.17763.7678 | 10.0.17763.7678 |
| microsoft | windows_10_21h2 | < 10.0.19044.6216 | 10.0.19044.6216 |
| microsoft | windows_10_22h2 | < 10.0.19045.6216 | 10.0.19045.6216 |
| microsoft | windows_10_version_1507 | >= 10.0.10240.0 < 10.0.10240.21100 | 10.0.10240.21100 |
| microsoft | windows_10_version_1607 | >= 10.0.14393.0 < 10.0.14393.8330 | 10.0.14393.8330 |
| microsoft | windows_10_version_1809 | >= 10.0.17763.0 < 10.0.17763.7678 | 10.0.17763.7678 |
| microsoft | windows_10_version_21h2 | >= 10.0.19044.0 < 10.0.19044.6216 | 10.0.19044.6216 |
| microsoft | windows_10_version_22h2 | >= 10.0.19045.0 < 10.0.19045.6216 | 10.0.19045.6216 |
| microsoft | windows_11_22h2 | < 10.0.22621.5768 | 10.0.22621.5768 |
| microsoft | windows_11_23h2 | < 10.0.22631.5768 | 10.0.22631.5768 |
| microsoft | windows_11_24h2 | < 10.0.26100.4851 | 10.0.26100.4851 |
| microsoft | windows_11_version_22h2 | >= 10.0.22621.0 < 10.0.22621.5768 | 10.0.22621.5768 |
| microsoft | windows_11_version_22h3 | >= 10.0.22631.0 < 10.0.22631.5768 | 10.0.22631.5768 |
| microsoft | windows_11_version_23h2 | >= 10.0.22631.0 < 10.0.22631.5768 | 10.0.22631.5768 |
| microsoft | windows_11_version_24h2 | >= 10.0.26100.0 < 10.0.26100.4946 | 10.0.26100.4946 |
| microsoft | windows_server_2008 | — | — |
| microsoft | windows_server_2008_r2_service_pack_1 | >= 6.1.7601.0 < 6.1.7601.27872 | 6.1.7601.27872 |
| microsoft | windows_server_2008_service_pack_2 | >= 6.0.6003.0 < 6.0.6003.23471 | 6.0.6003.23471 |
| microsoft | windows_server_2012 | — | — |
| microsoft | windows_server_2012 | >= 6.2.9200.0 < 6.2.9200.25622 | 6.2.9200.25622 |
| microsoft | windows_server_2012_r2 | >= 6.3.9600.0 < 6.3.9600.22725 | 6.3.9600.22725 |
| microsoft | windows_server_2016 | < 10.0.14393.8330 | 10.0.14393.8330 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_msrc7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Windows Installer Elevation of Privilege Vulnerability
vendor_msrc·2025-08-12·CVSS 7.8
CVE-2025-50173 [HIGH] CWE-1390 Windows Installer Elevation of Privilege Vulnerability
Windows Installer Elevation of Privilege Vulnerability
Description: Weak authentication in Windows Installer allows an authorized attacker to elevate privileges locally.
FAQ: What privileges could be gained by an attacker who successfully exploited this vulnerability?
An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.
Windows Installer: Windows Installer
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Elevation of Privilege
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely
Remediation: Release Notes
Reference: https://learn.microsoft.com/en-us/azure/virtual-desktop/whats-new-multimedia-redirection
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5063877
Refere
GHSA
GHSA-c5jq-762r-q8rg: Weak authentication in Windows Installer allows an authorized attacker to elevate privileges locally
ghsa_unreviewed·2025-08-12
CVE-2025-50173 [HIGH] CWE-1390 GHSA-c5jq-762r-q8rg: Weak authentication in Windows Installer allows an authorized attacker to elevate privileges locally
Weak authentication in Windows Installer allows an authorized attacker to elevate privileges locally.
No detection rules found.
No public exploits indexed.
Bleepingcomputer
Microsoft fixes app install issues caused by August Windows updates
blogs_bleepingcomputer·2025-09-10·CVSS 7.8
CVE-2025-50173 [HIGH] Microsoft fixes app install issues caused by August Windows updates
## Microsoft fixes app install issues caused by August Windows updates
## Sergiu Gatlan
Microsoft has fixed a known issue caused by the August 2025 security updates, which triggers unexpected User Account Control (UAC) prompts and app installation problems for non-admin users on all Windows versions.
This issue is caused by a security patch that mitigates a Windows Installer privilege escalation vulnerability ( CVE-2025-50173 ), which can enable authenticated attackers to gain SYSTEM privileges.
To address the CVE-2025-50173 security flaw, Microsoft has implemented new User Account Control (UAC) prompts requesting admin credentials in various situations to prevent attackers from escalating permissions.
However, these UAC prompts would also be displayed inadvertently in other scenarios
Bleepingcomputer
Microsoft August 2025 Patch Tuesday fixes one zero-day, 107 flaws
blogs_bleepingcomputer·2025-08-12·CVSS 7.2
[HIGH] Microsoft August 2025 Patch Tuesday fixes one zero-day, 107 flaws
## Microsoft August 2025 Patch Tuesday fixes one zero-day, 107 flaws
## Lawrence Abrams
44 Elevation of Privilege Vulnerabilities
35 Remote Code Execution Vulnerabilities
18 Information Disclosure Vulnerabilities
4 Denial of Service Vulnerabilities
9 Spoofing Vulnerabilities
When BleepingComputer reports on the Patch Tuesday security updates, we only count those released on Patch Tuesday. Therefore, the number of flaws does not include Mariner, Azure, and Microsoft Edge bugs fixed earlier this month.
To learn more about the non-security updates released today, you can review our dedicated articles on the Windows 11 KB5063878 & KB5063875 cumulative updates and the Windows 10 KB5063709 cumulative update .
## One publicly disclosed zero-day fixed
This month's Patch Tuesday fixes one
2025-08-12
Published