CVE-2025-50173

Description

Weak authentication in Windows Installer allows an authorized attacker to elevate privileges locally.

Risk Information

Base Score
7.8
MODERATE
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.177

Associated Vulnerability

VulnerabilityOS Platform
Windows Graphics Component Elevation of Privilege Vulnerability for Windows 10 Version 1507 for x64-based Systems (KB5063889)Windows
Windows Graphics Component Elevation of Privilege Vulnerability for Windows 10 Version 1507 for x86-based Systems (KB5063889)Windows
Windows Graphics Component Elevation of Privilege Vulnerability for Windows Server 2016 for x64-based Systems (KB5063871)Windows
Windows Graphics Component Elevation of Privilege Vulnerability for Windows 10 Version 1607 for x86-based Systems (KB5063871)Windows
Windows Graphics Component Elevation of Privilege Vulnerability for Windows 10 Version 1607 for x64-based Systems (KB5063871)Windows
Windows Graphics Component Elevation of Privilege Vulnerability for Windows Server 2019 for x64-based Systems (KB5063877)Windows
Windows Graphics Component Elevation of Privilege Vulnerability for Windows 10 Version 1809 for x86-based Systems (KB5063877)Windows
Windows Graphics Component Elevation of Privilege Vulnerability for Windows 10 Version 1809 for x64-based Systems (KB5063877)Windows
Windows Graphics Component Elevation of Privilege Vulnerability for Windows 10 Version 21H2 for x64-based Systems (KB5063709)Windows
Windows Graphics Component Elevation of Privilege Vulnerability for Windows 10 Version 22H2 for x86-based Systems (KB5063709)Windows
Windows Graphics Component Elevation of Privilege Vulnerability for Windows 10 Version 21H2 for x86-based Systems (KB5063709)Windows
Windows Graphics Component Elevation of Privilege Vulnerability for Windows 10 Version 22H2 for x64-based Systems (KB5063709)Windows
Windows Graphics Component Elevation of Privilege Vulnerability for Windows 11 Version 22H2 for arm64-based Systems (KB5063875)Windows
Windows Graphics Component Elevation of Privilege Vulnerability for Windows 11 Version 23H2 for x64-based Systems (KB5063875)Windows
Windows Graphics Component Elevation of Privilege Vulnerability for Windows 11 Version 23H2 for arm64-based Systems (KB5063875)Windows
Windows Graphics Component Elevation of Privilege Vulnerability for Windows 11 Version 22H2 for x64-based Systems (KB5063875)Windows
Windows Graphics Component Elevation of Privilege Vulnerability for Windows Server 2008 for x86-based Systems (KB5063948) (ESU)Windows
Windows Graphics Component Elevation of Privilege Vulnerability for Windows Server 2008 for x64-based Systems (KB5063948) (ESU)Windows
Windows Graphics Component Elevation of Privilege Vulnerability for Windows Server 2008 R2 for x64-based Systems (KB5063927) (ESU)Windows
Windows Graphics Component Elevation of Privilege Vulnerability for Windows Server 2012 for x64-based Systems (KB5063906) (ESU)Windows
Windows Graphics Component Elevation of Privilege Vulnerability for Windows Server 2012 R2 for x64-based Systems (KB5063950) (ESU)Windows
Windows Graphics Component Elevation of Privilege Vulnerability for Microsoft server operating system version 23H2 for x64-based Systems (KB5063899)Windows
2025-08 Cumulative Update for Windows 11 Version 24H2 for arm64-based Systems (KB5063878) (26100.4946)Windows
2025-08 Cumulative Update for Windows 11 Version 24H2 for x64-based Systems (KB5063878) (26100.4946)Windows
2025-08 Cumulative Update for Microsoft server operating system version 24H2 for x64-based Systems (KB5063878) (26100.4946)Windows
Windows Graphics Component Elevation of Privilege Vulnerability for Windows Server 2008 R2 for x64-based Systems (KB5063947) (ESU)Windows
Windows Graphics Component Elevation of Privilege Vulnerability for Microsoft server operating system version 21H2 for x64-based Systems (KB5063880)Windows
Windows Graphics Component Elevation of Privilege Vulnerability for Windows Server 2008 for x86-based Systems (KB5063888) (ESU)Windows
Windows Graphics Component Elevation of Privilege Vulnerability for Windows Server 2008 for x64-based Systems (KB5063888) (ESU)Windows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-421352025-08 Cumulative Update for Windows 10 Version 1507 for x64-based Systems (KB5063889)
PATCH-421362025-08 Cumulative Update for Windows 10 Version 1507 for x86-based Systems (KB5063889)
PATCH-421202025-08 Cumulative Update for Windows Server 2016 for x64-based Systems (KB5063871)
PATCH-421212025-08 Cumulative Update for Windows 10 Version 1607 for x86-based Systems (KB5063871)
PATCH-421222025-08 Cumulative Update for Windows 10 Version 1607 for x64-based Systems (KB5063871)
PATCH-421302025-08 Cumulative Update for Windows Server 2019 for x64-based Systems (KB5063877)
PATCH-421312025-08 Cumulative Update for Windows 10 Version 1809 for x86-based Systems (KB5063877)
PATCH-421322025-08 Cumulative Update for Windows 10 Version 1809 for x64-based Systems (KB5063877)
PATCH-421372025-08 Cumulative Update for Windows 10 Version 21H2 for x64-based Systems (KB5063709)
PATCH-421382025-08 Cumulative Update for Windows 10 Version 22H2 for x86-based Systems (KB5063709)
PATCH-421392025-08 Cumulative Update for Windows 10 Version 21H2 for x86-based Systems (KB5063709)
PATCH-421402025-08 Cumulative Update for Windows 10 Version 22H2 for x64-based Systems (KB5063709)
PATCH-421232025-08 Cumulative Update for Windows 11 Version 22H2 for arm64-based Systems (KB5063875)
PATCH-421242025-08 Cumulative Update for Windows 11 Version 23H2 for x64-based Systems (KB5063875)
PATCH-421252025-08 Cumulative Update for Windows 11 Version 23H2 for arm64-based Systems (KB5063875)
PATCH-421262025-08 Cumulative Update for Windows 11 Version 22H2 for x64-based Systems (KB5063875)
PATCH-421132025-08 Security Only Quality Update for Windows Server 2008 for x86-based Systems (KB5063948) (ESU)
PATCH-421142025-08 Security Only Quality Update for Windows Server 2008 for x64-based Systems (KB5063948) (ESU)
PATCH-421122025-08 Security Only Quality Update for Windows Server 2008 R2 for x64-based Systems (KB5063927) (ESU)
PATCH-421192025-08 Security Monthly Quality Rollup for Windows Server 2012 for x64-based Systems (KB5063906) (ESU)
PATCH-421182025-08 Security Monthly Quality Rollup for Windows Server 2012 R2 for x64-based Systems (KB5063950) (ESU)
PATCH-421342025-08 Cumulative Update for Microsoft server operating system version 23H2 for x64-based Systems (KB5063899)
PATCH-421272025-08 Cumulative Update for Windows 11 Version 24H2 for arm64-based Systems (KB5063878) (26100.4946) (CVE-2025-53779)
PATCH-421282025-08 Cumulative Update for Windows 11 Version 24H2 for x64-based Systems (KB5063878) (26100.4946) (CVE-2025-53779)
PATCH-421292025-08 Cumulative Update for Microsoft server operating system version 24H2 for x64-based Systems (KB5063878) (26100.4946) (CVE-2025-53779)
PATCH-421152025-08 Security Monthly Quality Rollup for Windows Server 2008 R2 for x64-based Systems (KB5063947) (ESU)
PATCH-421332025-08 Cumulative Update for Microsoft server operating system version 21H2 for x64-based Systems (KB5063880)
PATCH-421162025-08 Security Monthly Quality Rollup for Windows Server 2008 for x86-based Systems (KB5063888) (ESU)
PATCH-421172025-08 Security Monthly Quality Rollup for Windows Server 2008 for x64-based Systems (KB5063888) (ESU)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234