vendor:
Windows 10
by:
nu11secur1ty
7.8
CVSS
HIGH
Windows Installer Elevation of Privilege Vulnerability
284
CWE
Product Name: Windows 10
Affected Version From: Windows 10
Affected Version To: Windows 10
Patch Exists: YES
Related CWE: CVE-2020-0683
CPE: cpe:2.3:o:microsoft:windows_10:-
Platforms Tested: Windows
2020
MSI Packages Symbolic Links Processing – Windows 10 Privilege Escalation
An elevation of privilege vulnerability exists in the Windows Installer when MSI packages process symbolic links. An attacker who successfully exploited this vulnerability could bypass access restrictions to add or remove files.
Mitigation:
The security update addresses the vulnerability by modifying how reparse points are handled by the Windows Installer.