Vulnerability record · CVE-2020-0683 · published 11 February 2020
CVE-2020-0683: Windows Installer MSI symbolic link handling privilege escalation
Microsoft · Windows 10 1507
Windows Installer mishandles symbolic links while processing MSI packages, allowing a local user to follow a crafted link and gain elevated privileges. The flaw affects a broad set of Windows client and server releases, and Microsoft patched it in February 2020. Because it is a local privilege escalation in a core component, it is useful to attackers who already have a foothold.
Description
An elevation of privilege vulnerability exists in the Windows Installer when MSI packages process symbolic links, aka 'Windows Installer Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0686.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityIt is a locally exploitable elevation of privilege flaw with confirmed in-the-wild exploitation per CISA KEV and a high EPSS percentile, though it requires an existing foothold.
What it is
Windows Installer mishandles symbolic links while processing MSI packages, allowing a local user to follow a crafted link and gain elevated privileges. The flaw affects a broad set of Windows client and server releases, and Microsoft patched it in February 2020. Because it is a local privilege escalation in a core component, it is useful to attackers who already have a foothold.
Impact
An attacker who can run code on the host can escalate from a low-privileged account to SYSTEM or administrative rights. That access enables credential theft, persistence and further lateral movement.
Attack surface
The vector is local (AV:L) with low privileges required (PR:L) and no user interaction (UI:N), so the attacker must already have code execution or an interactive session on the target. No network exposure or victim action is needed beyond running the crafted MSI or triggering the link processing.
Exploitation
CISA added this to the Known Exploited Vulnerabilities catalog on 2021-11-03, confirming exploitation in the wild, and EPSS shows a 30-day probability of about 7.7 percent (94th percentile). No ransomware campaign use is documented in the record.
What to do
- Apply the Microsoft security update for CVE-2020-0683 on all affected Windows client and server versions, prioritizing internet-facing and multi-user systems.
- Restrict local administrative rights and enforce least privilege so a compromised low-privileged account cannot easily reach the vulnerable MSI processing path.
- Harden MSI handling where feasible, for example by controlling who can install packages and monitoring for unusual msiexec.exe invocations.
- Track CISA KEV remediation deadlines and verify patching through vulnerability scanning or configuration baselines.
Detection
- Monitor for msiexec.exe processes that create or follow symbolic links in user-writable or temporary directories.
- Alert on unexpected elevation of low-privileged processes to SYSTEM or administrative tokens shortly after MSI installation activity.
- Audit Windows Installer and process creation logs for msiexec.exe spawned from unusual parent processes or user profile paths.
- Correlate local privilege escalation events with known post-exploitation behavior such as credential dumping or new service creation.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2020-0683 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Microsoft Windows Installer Privilege Escalation Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.
Affected products
17 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0683 | PatchVendor Advisory |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0683 | PatchVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-0683 | US Government Resource |
Track CVE-2020-0683 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-0683), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.