CVE-2020-16902: Windows Installer Elevation of Privilege Vulnerability

Overview

Severity
High (CVSS 7.8)
CVSS Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C
Category
Elevation of Privilege
Exploit Status
Not Exploited
Exploitation Likelihood
Less Likely
Patch Tuesday
2020-Oct
Released
2020-10-13
EPSS Score
0.48% (percentile: 64.9%)

Description

An elevation of privilege vulnerability exists in the Windows Installer when the Windows Installer fails to properly sanitize input leading to an insecure library loading behavior. A locally authenticated attacker could run arbitrary code with elevated system privileges. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. The security update addresses the vulnerability by correcting the input sanitization error to preclude unintended elevation.

Affected Products (44)

Other

  • 11497
  • 11498
  • 11563
  • 11568
  • 11569
  • 11570
  • 11571
  • 11572
  • 11712
  • 11713
  • 11714
  • 11715
  • 11453
  • 11454
  • 11583
  • 11644
  • 11645
  • 11646
  • 11647
  • 11766
  • 11767
  • 11768
  • 11769
  • 10729
  • 10735
  • 10852
  • 10853
  • 10816
  • 10855
  • 10047
  • 10048
  • 10481
  • 10482
  • 10484
  • 9312
  • 10287
  • 9318
  • 9344
  • 10051
  • 10049
  • 10378
  • 10379
  • 10483
  • 10543

Security Updates (15)

Acknowledgments

Abdelhamid Naceri (halov), an independent security researcher working for <a href="https://ssd-disclosure.com/">SSD Secure Disclosure </a>

Revision History

  • 2020-10-13: Information published.