Link following in Microsoft Windows and Windows Server - CVE-2022-24499
Published: April 12, 2022 / Updated: June 1, 2022
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to insecure link following in the the Windows Installer service. A local user can create a symbolic link to an arbitrary file on the system and modify its permissions. As a result, a local user can later modify this file and escalate privileges on the system.
Affected software
Windows Server