New Search

Windows Installer Elevation of Privilege Vulnerability - CVE-2020-16902

oval:org.cisecurity:def:8420

An elevation of privilege vulnerability exists in the Windows Installer when the Windows Installer fails to properly sanitize input leading to an insecure library loading behavior. A locally authenticated attacker could run arbitrary code with elevated system privileges. An attacker could then install programs; view change or delete data; or create new accounts with full user rights. The security update addresses the vulnerability by correcting the input sanitization error to preclude unintended elevation.

Family:
windows
Status:
ACCEPTED
Platform(s):
  • Microsoft Windows Server 2016
  • Microsoft Windows 10
  • Microsoft Windows Server 2012
  • Microsoft Windows Server 2008 R2
  • Microsoft Windows Server 2012 R2
  • Microsoft Windows Server 2008
  • Microsoft Windows 8.1
  • Microsoft Windows 7
  • Microsoft Windows Server 2019
Class:
vulnerability
Reference(s):
  • CVE-2020-16902
  • MSRC-CVE-2020-16902
  • KB4580387
  • KB4580385
  • KB4580353
  • KB4580358
  • KB4580327
  • KB4580346
  • KB4580328
  • KB4580330
  • KB4577668
  • KB4577671
  • KB4579311
Product(s):