« Back to list

Microsoft

Microsoft Windows Installer: vulnerabilities and CVEs

Microsoft Windows Installer has 2 published vulnerabilities, 1 of them in the last 12 months. 0 are rated critical and 0 are listed by CISA as actively exploited.

CVEs2
Last 12 months1
Critical0
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-82649High (7)0.17%—Aug 30, 2026
SiYuan Windows installer before version 3.8.1 (affected versions >= 2.0.14) contains an uncontrolled search path element vulnerability in its NSIS installer, which invokes system executables such as TASKKILL by name…
CVE-2008-2547High (9.3)8.5%—Jun 4, 2008
Stack-based buffer overflow in msiexec.exe 3.1.4000.1823 and 4.5.6001.22159 in Microsoft Windows Installer allows context-dependent attackers to execute arbitrary code via a long GUID value for the /x (aka /uninstall)…

🎯 How it gets exploited (ATT&CK techniques)

  1. T1203 Exploitation for Client Execution1
  2. T1574.007 Path Interception by PATH Environment Variable1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by Microsoft