Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5x7v-x3pp-6x6m

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7

Описание

An elevation of privilege vulnerability exists in the Windows Installer when the Windows Installer fails to properly sanitize input leading to an insecure library loading behavior, aka "Windows Installer Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.

An elevation of privilege vulnerability exists in the Windows Installer when the Windows Installer fails to properly sanitize input leading to an insecure library loading behavior, aka "Windows Installer Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.

EPSS

Процентиль: 53%
0.00302
Низкий

7 High

CVSS3

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 7
nvd
почти 7 лет назад

An elevation of privilege vulnerability exists in the Windows Installer when the Windows Installer fails to properly sanitize input leading to an insecure library loading behavior, aka "Windows Installer Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.

CVSS3: 7.4
msrc
почти 7 лет назад

Windows Installer Elevation of Privilege Vulnerability

CVSS3: 7.4
fstec
почти 7 лет назад

Уязвимость компонента Windows Installer операционных систем Windows, позволяющая нарушителю повысить свои привилегии

EPSS

Процентиль: 53%
0.00302
Низкий

7 High

CVSS3

Дефекты

CWE-20