CVE-2020-16902: Windows Installer Elevation of Privilege Vulnerability
Overview
- Severity
- High (CVSS 7.8)
- CVSS Vector
- CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C
- Category
- Elevation of Privilege
- Exploit Status
- Not Exploited
- Exploitation Likelihood
- Less Likely
- Patch Tuesday
- 2020-Oct
- Released
- 2020-10-13
- EPSS Score
- 0.48% (percentile: 64.9%)
Description
An elevation of privilege vulnerability exists in the Windows Installer when the Windows Installer fails to properly sanitize input leading to an insecure library loading behavior.
A locally authenticated attacker could run arbitrary code with elevated system privileges. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
The security update addresses the vulnerability by correcting the input sanitization error to preclude unintended elevation.
Affected Products (44)
Other
- 11497
- 11498
- 11563
- 11568
- 11569
- 11570
- 11571
- 11572
- 11712
- 11713
- 11714
- 11715
- 11453
- 11454
- 11583
- 11644
- 11645
- 11646
- 11647
- 11766
- 11767
- 11768
- 11769
- 10729
- 10735
- 10852
- 10853
- 10816
- 10855
- 10047
- 10048
- 10481
- 10482
- 10484
- 9312
- 10287
- 9318
- 9344
- 10051
- 10049
- 10378
- 10379
- 10483
- 10543
Security Updates (15)
Acknowledgments
Abdelhamid Naceri (halov), an independent security researcher working for <a href="https://ssd-disclosure.com/">SSD Secure Disclosure </a>
Revision History
- 2020-10-13: Information published.