Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9qvm-6h84-98c2

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

An elevation of privilege vulnerability exists in the Windows Installer when the Windows Installer fails to properly sanitize input leading to an insecure library loading behavior.A locally authenticated attacker could run arbitrary code with elevated system privileges, aka 'Windows Installer Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1277, CVE-2020-1302, CVE-2020-1312.

An elevation of privilege vulnerability exists in the Windows Installer when the Windows Installer fails to properly sanitize input leading to an insecure library loading behavior.A locally authenticated attacker could run arbitrary code with elevated system privileges, aka 'Windows Installer Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1277, CVE-2020-1302, CVE-2020-1312.

EPSS

Процентиль: 72%
0.0073
Низкий

Дефекты

CWE-269

Связанные уязвимости

CVSS3: 7.8
nvd
около 5 лет назад

An elevation of privilege vulnerability exists in the Windows Installer when the Windows Installer fails to properly sanitize input leading to an insecure library loading behavior.A locally authenticated attacker could run arbitrary code with elevated system privileges, aka 'Windows Installer Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1277, CVE-2020-1302, CVE-2020-1312.

CVSS3: 7.8
msrc
около 5 лет назад

Windows Installer Elevation of Privilege Vulnerability

CVSS3: 7.8
fstec
около 5 лет назад

Уязвимость компонента Windows Installer операционных систем Microsoft Windows, позволяющая нарушителю повысить свои привилегии

EPSS

Процентиль: 72%
0.0073
Низкий

Дефекты

CWE-269