← KEV catalog
CISA known exploited vulnerability

CVE-2020-0683

Microsoft Windows Installer Privilege Escalation Vulnerability

SOURCE FACT

Microsoft · Windows

Microsoft Windows Installer contains a privilege escalation vulnerability when MSI packages process symbolic links, which allows attackers to bypass access restrictions to add or remove files.

Required action

Apply updates per vendor instructions.

CISA notes

https://nvd.nist.gov/vuln/detail/CVE-2020-0683

View source evidence →

CHECK YOUR OUTSIDE-IN INVENTORY

Could this product be present?