EXPOSURES › CVE-2020-0683
CVE-2020-0683
HIGH ⌖ ON CISA KEV · EXPLOITEDWindows Installer privilege escalation via symbolic link processing allows attackers to bypass access restrictions and add/remove files.
This vulnerability enables attackers to escalate privileges by manipulating symbolic links during MSI package processing, bypassing access controls to modify system files. DIB organizations must ensure Windows systems are patched promptly, as this flaw was actively exploited in the wild and could lead to unauthorized system modifications or data exfiltration. The failure stems from improper handling of symbolic links, a known issue that Microsoft eventually patched but left systems vulnerable for a period.
Shame score — A privilege escalation flaw in a core OS component that was actively exploited in the wild, indicating a significant gap in Microsoft's patching or vulnerability disclosure timeline.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Windows Installer contains a privilege escalation vulnerability when MSI packages process symbolic links, which allows attackers to bypass access restrictions to add or remove files.
"Microsoft Windows Installer contains a privilege escalation vulnerability when MSI packages process symbolic links, which allows attackers to bypass access restrictions to add or remove files."
| PRODUCT | STATUS |
|---|---|
| Azure Commercial Cloud Microsoft |
Authorized |
| Azure Government (includes Dynamics 365) Microsoft |
Authorized |
| Microsoft Office 365 GCC High Microsoft |
In Process |
| Office 365 Multi-Tenant & Supporting Services Microsoft |
Authorized |