Privilege Escalation Vulnerability in Microsoft Windows Package Manager
A local privilege escalation vulnerability in the Microsoft Windows Package Manager allows an authenticated local attacker to gain elevated privileges on the host system.
CVE search metadata
CVE search record: CVE-2024-38062. Severity: high. CVSS: 7.8. EPSS: 1.61%. KEV: no. Product: Windows Package Manager. Brief: Privilege Escalation Vulnerability in Microsoft Windows Package Manager. Brief link: https://feed.craftedsignal.io/briefs/2026-08-windows-package-manager-lpe/
Microsoft has disclosed a security vulnerability affecting the Windows Package Manager (winget) that facilitates local privilege escalation. This issue, tracked as CVE-2024-38062, allows a local, authenticated user to exploit flaws within the package manager's execution or installation logic to execute code with elevated permissions. Because the Windows Package Manager is a central component for managing system software, this vulnerability poses a risk to system integrity in environments where non-administrative users are permitted to execute package management commands or where automated deployment scripts interact with the tool. Defenders should prioritize patching, as this vulnerability requires local access to a system to successfully trigger the escalation.
Impact
Successful exploitation of this vulnerability enables an attacker with local access to elevate their account privileges. This can result in complete system compromise, unauthorized access to sensitive data, and the ability to install persistent malware. The vulnerability affects all systems utilizing the Microsoft Windows Package Manager on supported versions of Windows.
Recommendation
- Apply the security updates provided by Microsoft for the Windows Package Manager component to address CVE-2024-38062.
- Audit environments to identify the presence and version of the Windows Package Manager.
- Review system logs for unusual package installations or unexpected process executions originating from the winget.exe process.
Mitigations
Patch Windows Package Manager across the enterprise
CVE-2024-38062