CVE-2020-0683
KEVmassLocal Privilege Escalation in Microsoft Windows Installer (Symbolic Link Handling)
CISA: Microsoft Windows Installer Privilege Escalation Vulnerability
CVE-2020-0683 is an elevation-of-privilege flaw in the Windows Installer (MSI) engine, classified as improper link resolution before file access (CWE-59): when the elevated Installer processes an MSI package, it can be made to follow attacker-controlled symbolic links. A local attacker holding only a low-privileged account can trigger or race an MSI installation so that the Installer's SYSTEM-level file operations are redirected through crafted symlinks into protected locations, with no user interaction required. Successful exploitation yields local privilege escalation to SYSTEM (CVSS 3.1 7.8, C:H/I:H/A:H), giving the attacker full control of the host, which is useful for disabling defenses and staging follow-on activity. Any unpatched system running an affected release is exposed — per the CPE data, Windows 7, Windows 8.1, Windows RT 8.1, Windows 10 versions 1507 through 1909, and Windows Server versions 1803 and 1903. CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2021-11-03, confirming in-the-wild exploitation (ransomware use unknown); EPSS currently estimates a 7.7% probability of exploitation within 30 days (94th percentile), and no public proof-of-concept is known.
What to do: Apply Microsoft's February 2020 Patch Tuesday updates — or any later cumulative update/monthly rollup — to all Windows 7, 8.1, RT 8.1, Windows 10 (1507–1909), and Windows Server 1803/1903 systems, and verify the related sibling vulnerability CVE-2020-0686 is also addressed by the installed patch; CISA's KEV listing requires remediation per vendor instructions. Prioritize endpoints and shared/multi-user servers where untrusted or low-privileged users can run MSI installers, and sweep inventories for machines that skipped the February 2020 patch cycle. In the absence of a public PoC, treat MSI installation activity launched by non-administrative accounts as a possible indicator of exploitation attempts.
| Microsoft Windows 10 | 1507, 1607, 1709, 1803, 1809, 1903, 1909 (pre-February 2020 security updates) |
| Microsoft Windows 7 | all supported builds prior to the February 2020 security update |
| Microsoft Windows 8.1 | all supported builds prior to the February 2020 security update |
| Microsoft Windows RT 8.1 | prior to the February 2020 security update |
| Microsoft Windows Server | version 1803 and version 1903 (Semi-Annual Channel releases, pre-February 2020 security updates) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An elevation of privilege vulnerability exists in the Windows Installer when MSI packages process symbolic links, aka 'Windows Installer Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0686.
- Affected
- Microsoft Windows
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- microsoft
- Products
- windows 10 1507, windows 10 1607, windows 10 1709, windows 10 1803, windows 10 1809, windows 10 1903, windows 10 1909, windows 7, windows 8.1, windows rt 8.1, windows server 1803, windows server 1903
- Weakness
- CWE-59
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H