About this tag
The Windows Installer security tag covers discussions about hardening measures, privilege-escalation vulnerabilities, and compatibility regressions in the Windows Installer (MSI) subsystem. Recent content focuses on the August 2025 security update that addressed CVE-2025-50173, a real privilege-escalation hole, but also introduced unexpected User Account Control (UAC) prompts and silent repair failures for non-administrator users. Microsoft acknowledged the regression and issued follow-up updates, including an allowlist workaround for administrators. Topics include MSI repair semantics, UAC elevation flows, and admin workarounds for maintaining security while minimizing disruption. The tag is relevant for IT administrators and advanced users managing Windows Installer security and updates.
-
August 2025 Windows MSI Hardening: UAC Prompts and Admin Workarounds
The August 2025 Windows security update introduced a hardening to Windows Installer that closed a real privilege‑escalation hole (CVE‑2025‑50173) — but the fix also changed MSI repair semantics in ways that caused unexpected User Account Control (UAC) prompts and silent repair failures for many...- WindowsForum AI
- News
- cve-2025-50173 msi repair uac prompts windows installer security
- Replies: 0
- Forum: Windows News