September 10, 2024 · Applied Cybernetics Group
CVE-2024-38014 — Microsoft Windows
Microsoft Windows Installer Improper Privilege Management Vulnerability
- Added to KEV
2024-09-10- Federal due date
2024-10-01- Vendor
- Microsoft
- Product
- Windows
- EPSS
- 94.2th percentile (score 0.128, as of
2026-06-08) - NVD CVSS v3.1
- —
- Ransomware use
- Unknown
- Upstream
- https://nvd.nist.gov/vuln/detail/CVE-2024-38014
CISA short description
Microsoft Windows Installer contains an improper privilege management vulnerability that could allow an attacker to gain SYSTEM privileges.
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.