CVE-2020-0683: Microsoft Windows Installer Privilege Escalation Vulnerability
An elevation of privilege vulnerability exists in the Windows Installer when MSI packages process symbolic links, aka 'Windows Installer Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0686.
Other sources
Microsoft Windows Installer contains a privilege escalation vulnerability when MSI packages process symbolic links, which allows attackers to bypass access restrictions to add or remove files.
— CISA
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2020-0683?
CVE-2020-0683 is rated as important by Microsoft due to its potential for elevation of privilege.
How do I fix CVE-2020-0683?
To fix CVE-2020-0683, apply the latest security updates provided by Microsoft for your affected Windows version.
Which versions of Windows are affected by CVE-2020-0683?
CVE-2020-0683 affects multiple versions of Windows, including Windows 7, 8.1, 10, and several Windows Server editions.
What is the impact of exploiting CVE-2020-0683?
Exploiting CVE-2020-0683 could allow an attacker to elevate their privileges and perform restricted actions on the system.
Is CVE-2020-0683 unique from CVE-2020-0686?
Yes, CVE-2020-0683 is a distinct vulnerability and should not be confused with CVE-2020-0686.