ZeroHour

CVE-2020-0683

KEVmass

Local Privilege Escalation in Microsoft Windows Installer (Symbolic Link Handling)

CISA: Microsoft Windows Installer Privilege Escalation Vulnerability

CVSS 3.1
7.8 high
EPSS
8%p94
Published
()
KEV added
AI analysis

CVE-2020-0683 is an elevation-of-privilege flaw in the Windows Installer (MSI) engine, classified as improper link resolution before file access (CWE-59): when the elevated Installer processes an MSI package, it can be made to follow attacker-controlled symbolic links. A local attacker holding only a low-privileged account can trigger or race an MSI installation so that the Installer's SYSTEM-level file operations are redirected through crafted symlinks into protected locations, with no user interaction required. Successful exploitation yields local privilege escalation to SYSTEM (CVSS 3.1 7.8, C:H/I:H/A:H), giving the attacker full control of the host, which is useful for disabling defenses and staging follow-on activity. Any unpatched system running an affected release is exposed — per the CPE data, Windows 7, Windows 8.1, Windows RT 8.1, Windows 10 versions 1507 through 1909, and Windows Server versions 1803 and 1903. CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2021-11-03, confirming in-the-wild exploitation (ransomware use unknown); EPSS currently estimates a 7.7% probability of exploitation within 30 days (94th percentile), and no public proof-of-concept is known.

What to do: Apply Microsoft's February 2020 Patch Tuesday updates — or any later cumulative update/monthly rollup — to all Windows 7, 8.1, RT 8.1, Windows 10 (1507–1909), and Windows Server 1803/1903 systems, and verify the related sibling vulnerability CVE-2020-0686 is also addressed by the installed patch; CISA's KEV listing requires remediation per vendor instructions. Prioritize endpoints and shared/multi-user servers where untrusted or low-privileged users can run MSI installers, and sweep inventories for machines that skipped the February 2020 patch cycle. In the absence of a public PoC, treat MSI installation activity launched by non-administrative accounts as a possible indicator of exploitation attempts.

Affected
Microsoft Windows 101507, 1607, 1709, 1803, 1809, 1903, 1909 (pre-February 2020 security updates)
Microsoft Windows 7all supported builds prior to the February 2020 security update
Microsoft Windows 8.1all supported builds prior to the February 2020 security update
Microsoft Windows RT 8.1prior to the February 2020 security update
Microsoft Windows Serverversion 1803 and version 1903 (Semi-Annual Channel releases, pre-February 2020 security updates)
Estimated exposure
masshundreds of millions of Windows devices (combined Windows 7/8.1/10 market share at the February 2020 disclosure) — The affected releases — Windows 7, 8.1, and Windows 10 1507 through 1909 — together made up the overwhelming majority of desktop operating systems in 2020, and the vulnerable Windows Installer component ships by default on every one of…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An elevation of privilege vulnerability exists in the Windows Installer when MSI packages process symbolic links, aka 'Windows Installer Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0686.

CISA Known Exploited Vulnerability
Affected
Microsoft Windows
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
microsoft
Products
windows 10 1507, windows 10 1607, windows 10 1709, windows 10 1803, windows 10 1809, windows 10 1903, windows 10 1909, windows 7, windows 8.1, windows rt 8.1, windows server 1803, windows server 1903
Weakness
CWE-59
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news