VYPR

Windows Installer

by Microsoft

CVEs (71)

  • CVE-2020-0843HigMar 12, 2020
    risk 0.51cvss 7.8epss 0.01

    An elevation of privilege vulnerability exists in Windows Installer because of the way Windows Installer handles certain filesystem operations.To exploit the vulnerability, an attacker would require unprivileged execution on the victim system, aka 'Windows Installer Elevation of…

  • CVE-2020-0842HigMar 12, 2020
    risk 0.51cvss 7.8epss 0.01

    An elevation of privilege vulnerability exists in Windows Installer because of the way Windows Installer handles certain filesystem operations.To exploit the vulnerability, an attacker would require unprivileged execution on the victim system, aka 'Windows Installer Elevation of…

  • CVE-2020-0814HigMar 12, 2020
    risk 0.51cvss 7.8epss 0.01

    An elevation of privilege vulnerability exists in Windows Installer because of the way Windows Installer handles certain filesystem operations.To exploit the vulnerability, an attacker would require unprivileged execution on the victim system, aka 'Windows Installer Elevation of…

  • CVE-2020-0798HigMar 12, 2020
    risk 0.51cvss 7.8epss 0.01

    An elevation of privilege vulnerability exists in the Windows Installer when the Windows Installer fails to properly sanitize input leading to an insecure library loading behavior.A locally authenticated attacker could run arbitrary code with elevated system privileges, aka…

  • CVE-2020-0686HigFeb 11, 2020
    risk 0.51cvss 7.8epss 0.01

    An elevation of privilege vulnerability exists in the Windows Installer when MSI packages process symbolic links, aka 'Windows Installer Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0683.

  • CVE-2019-1415HigNov 12, 2019
    risk 0.51cvss 7.8epss 0.01

    An elevation of privilege vulnerability exists in Windows Installer because of the way Windows Installer handles certain filesystem operations.To exploit the vulnerability, an attacker would require unprivileged execution on the victim system, aka 'Windows Installer Elevation of…

  • CVE-2019-0973HigJun 12, 2019
    risk 0.51cvss 7.8epss 0.01

    An elevation of privilege vulnerability exists in the Windows Installer when the Windows Installer fails to properly sanitize input leading to an insecure library loading behavior. A locally authenticated attacker could run arbitrary code with elevated system privileges. An…

  • CVE-2016-7292HigDec 20, 2016
    risk 0.51cvss 7.8epss 0.01

    The Installer in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 mishandles library loading, which allows local users to gain…

  • CVE-2025-21331HigJan 14, 2025
    risk 0.48cvss 7.3epss 0.01

    Windows Installer Elevation of Privilege Vulnerability

  • CVE-2023-32050HigJul 11, 2023
    risk 0.46cvss 7.0epss 0.00

    Windows Installer Elevation of Privilege Vulnerability

  • CVE-2023-24904HigMay 9, 2023
    risk 0.46cvss 7.1epss 0.01

    Windows Installer Elevation of Privilege Vulnerability

  • CVE-2023-21542HigJan 10, 2023
    risk 0.46cvss 7.0epss 0.00

    Windows Installer Elevation of Privilege Vulnerability

  • CVE-2021-28440HigApr 13, 2021
    risk 0.46cvss 7.0epss 0.01

    Windows Installer Elevation of Privilege Vulnerability

  • CVE-2021-26862HigMar 11, 2021
    risk 0.46cvss 7.0epss 0.01

    Windows Installer Elevation of Privilege Vulnerability

  • CVE-2018-8339HigAug 15, 2018
    risk 0.46cvss 7.0epss 0.01

    An elevation of privilege vulnerability exists in the Windows Installer when the Windows Installer fails to properly sanitize input leading to an insecure library loading behavior, aka "Windows Installer Elevation of Privilege Vulnerability." This affects Windows 7, Windows…

  • CVE-2018-0868HigMar 14, 2018
    risk 0.46cvss 7.0epss 0.01

    Windows Installer in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016 and Windows Server, version 1709 allows an elevation of privilege vulnerability…

  • CVE-2026-61938HigAug 11, 2026
    risk 0.45cvss 7.0epss 0.00

    Use after free in Windows Installer allows an authorized attacker to elevate privileges locally.

  • CVE-2021-33765MedJul 14, 2021
    risk 0.40cvss 6.2epss 0.01

    Windows Installer Spoofing Vulnerability

  • CVE-2021-26413MedApr 13, 2021
    risk 0.40cvss 6.2epss 0.01

    Windows Installer Spoofing Vulnerability

  • CVE-2025-29837MedMay 13, 2025
    risk 0.36cvss 5.5epss 0.01

    Improper link resolution before file access ('link following') in Windows Installer allows an authorized attacker to disclose information locally.