Link following in Microsoft Windows and Windows Server - CVE-2020-0683

 

Link following in Microsoft Windows and Windows Server - CVE-2020-0683

Published: February 11, 2020 / Updated: February 20, 2022


Vulnerability identifier: #VU25235
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-0683
CWE-ID: CWE-59
Exploitation vector: Local access
Exploit availability: The vulnerability is being exploited in the wild

Vulnerability details

The vulnerability allows a local user to elevate privileges on the system.

The vulnerability exists within the Windows Installer when MSI packages process symbolic links. A local user can bypass access restrictions to add or remove files and escalate privileges on the system.


Affected software

Microsoft Windows
Windows Server
Solutions Enabler Virtual Appliance
Solutions Enabler
Unisphere for PowerMax Virtual Appliance
Unisphere for PowerMax

How to mitigate CVE-2020-0683

Install updates from vendor's website.

Solutions Enabler Virtual Appliance - addressed in versions 9.0.0.19, 9.1.0.6
Solutions Enabler - addressed in versions 9.0.0.19, 9.1.0.6
Unisphere for PowerMax Virtual Appliance - addressed in versions 9.0.2.18, 9.1.0.17
Unisphere for PowerMax - addressed in versions 9.0.2.18, 9.1.0.17

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins