#VU62141 Link following in Windows and Windows Server - CVE-2022-24499
Published: April 12, 2022 / Updated: June 1, 2022
Windows
Windows Server
Microsoft
Description
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to insecure link following in the the Windows Installer service. A local user can create a symbolic link to an arbitrary file on the system and modify its permissions. As a result, a local user can later modify this file and escalate privileges on the system.