PT-2020-4267 · Microsoft · Windows Installer+1

Halov

·

Published

2020-10-13

·

Updated

2023-12-31

·

CVE-2020-16902

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Windows Installer (affected versions not specified)
Description: The issue exists due to insufficient input validation in the Windows Installer, leading to insecure library loading behavior. A locally authenticated attacker could exploit this to run arbitrary code with elevated system privileges, allowing them to install programs, view, change, or delete data, or create new accounts with full user rights.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

LPE

Improper Privilege Management

Weakness Enumeration

Related Identifiers

BDU:2020-04759
CVE-2020-16902

Affected Products

Windows
Windows Installer