SecPod

Learn Search

Search across all Learn content

← Back to Security Research
New Windows Installer Zero-Day Flaw exploited in the Wild

New Windows Installer Zero-Day Flaw exploited in the Wild

Microsoft recently patched a Windows Installer Elevation of Privilege vulnerability tracked as CVE-2021-41379 in its November Patch Tuesday. As we know, the security researcher Abdelhamid Naceri discovered and reported this vulnerability. But surprisingly, recently, he also found that the fix releas...

Nov 25, 2021By Ashwitha Kallalike3 min read

Microsoft recently patched a Windows Installer Elevation of Privilege vulnerability tracked as CVE-2021-41379 in its November Patch Tuesday. As we know, the security researcher Abdelhamid Naceri discovered and reported this vulnerability. But surprisingly, recently, he also found that the fix released by Microsoft can be bypassed and leveraged to achieve local privilege escalation. A Vulnerability Management Software can keep these attacks at bay.

Cisco Talos stated that it has already detected malware samples actively attempting to exploit this newly discovered Zero-Day bug. The earlier patched vulnerability had the ability to delete the targeted files on a system but not gain any privileges to modify or view the file contents. But this Zero-Day flaw is considered more powerful than it, as it can be used to replace any executable in the system with an MSI file and even allow attackers to run any code as an administrator. A good Vulnerability Management Tool can prevent these attacks.

About the Zero-Day vulnerability:

The Zero-Day flaw was present during the analysis of the patch for CVE-2021-41379. The researcher observes that the bug is not properly fixing and could be bypassing to gain the elevation privileges of an administrator. When the attacker is able to bypass the fix successfully, any normal user account attacker will be able to elevate his privileges to become an administrator. When the researcher could successfully exploit the PoC over a fully patched system. He overwrote the DACL (Discretionary Access Control List) for Microsoft Edge Elevation Service. Also, he could successfully replace any executable file on the system with an MSI file. As a result, it was possible for him to run any code on the system with administrative privileges. Although Microsoft is assigning a CVSS score of 5.5 and a temporal score of 4.8. Mentioning severity as a medium to the previous patch CVE, it is now additionally abusing after the release of the PoC by the researcher.

PoC:

On November 22nd, Naceri published a Proof-of-Concept (PoC) in Github that contained an exe file named InstallerFileTakeOver.exe. According to him, this is in execution in any support Windows versions that have a fully patched. This PoC overwrites Microsoft Edge’s elevation service DACL, copies itself to the service location, and executes it to gain elevated privileges. It may not work in Windows Server 2016 and 2019 as they don’t have the elevation service installed. The image below shows the PoC execution in a fully patched Windows 11, which overwrites the file’s access control list. “C:\Windows\system.ini” with the desiring users having administrative privileges. Further, it can replace any executable file on the system with an MSI file, allowing an attacker to run any code as an administrator.

plaintext

Credits: thehackernews

Impact of CVE-2021-41379:

Successful exploitation of this Zero-Day vulnerability allows an attacker to abuse the access gained to take over the compromised system fully. Download any software, delete, modify, or obtain any sensitive information stored in the machine.

Affected version by CVE-2021-41379

This CVE-2021-41379 affects every supported fully patched version of Microsoft Windows, including the installed November Patch Tuesday updates.

Solution

As of the publication of this blog, Microsoft is not releasing any patch for this vulnerability, and other fixed information is not present. There is no known workaround available due to the complexity of this vulnerability. As patching the binary would break Windows Installer. Microsoft is aware of the issue and is in expectation to patch the issue soon by releasing a security update.

We are tracking this issue for any updates and will religiously update the information once available.

Featured Posts

Open Citrix Sounds the Alarm: Two Critical NetScaler Zero-Days Actively Exploited
Citrix Sounds the Alarm: Two Critical NetScaler Zero-Days Actively Exploited

CVE Research

Citrix Sounds the Alarm: Two Critical NetScaler Zero-Days Actively Exploited

Citrix has released security updates for NetScaler ADC and NetScaler Gateway addressing CVE-2026-88771 and CVE-2026-88772, two critical remote code execution vulnerabilities. Exploits against unmitigated deployments have been observed. CVE-2026-88771 affects all deployments, including default configurations; CVE-2026-88772 applies when DTLS is enabled, including the default state on VPN virtual servers. This article covers impact, affected and fixed versions, how to confirm exposure, and recommended remediation.

Sep 28, 2026

Open CVE-2023-49105: The ownCloud Authentication Flaw That Exposed Sensitive Credentials
CVE-2023-49105: The ownCloud Authentication Flaw That Exposed Sensitive Credentials

CVE Research

CVE-2023-49105: The ownCloud Authentication Flaw That Exposed Sensitive Credentials

Sep 25, 2026

Open Patch Analysis & Exploitation Timeline: RouterOS SSH Attacks Predate Production Fixes in CISA's September 10, 2026 KEV Additions
Patch Analysis & Exploitation Timeline: RouterOS SSH Attacks Predate Production Fixes in CISA's September 10, 2026 KEV Additions

CVE Research

Patch Analysis & Exploitation Timeline: RouterOS SSH Attacks Predate Production Fixes in CISA's September 10, 2026 KEV Additions

Two MikroTik RouterOS CVEs entered CISA KEV seven days after production fixes. Dated reporting places SSH-chain exploitation involving CVE-2026-86060 at least one calendar day before those releases; no comparable start date is established for CVE-2026-67277.

Sep 25, 2026

Open Patch Analysis & Exploitation Timeline: A Day-Old Chrome Bug and an Eight-Month-Old Fortinet Flaw Share the Same KEV Batch
Patch Analysis & Exploitation Timeline: A Day-Old Chrome Bug and an Eight-Month-Old Fortinet Flaw Share the Same KEV Batch

CVE Research

Patch Analysis & Exploitation Timeline: A Day-Old Chrome Bug and an Eight-Month-Old Fortinet Flaw Share the Same KEV Batch

Four vulnerabilities added to CISA’s KEV catalog on September 9, 2026 show widely different timelines between public disclosure and formal exploitation-based prioritization, ranging from one day to 239 days.

Sep 24, 2026