SB2020021155 - Privilege escalation in Windows Installer
Published: February 11, 2020
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 2 secuirty vulnerabilities.
1) Link following (CVE-ID: CVE-2020-0683)
The vulnerability allows a local user to elevate privileges on the system.
The vulnerability exists within the Windows Installer when MSI packages process symbolic links. A local user can bypass access restrictions to add or remove files and escalate privileges on the system.
2) Link following (CVE-ID: CVE-2020-0686)
The vulnerability allows a local user to elevate privileges on the system.
The vulnerability exists within the Windows Installer when MSI packages process symbolic links. A local user can bypass access restrictions to add or remove files and escalate privileges on the system.Remediation
Install update from vendor's website.