Windows Installer
by Microsoft
CVEs (76)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-1078 | Hig | 0.51 | 7.8 | 0.01 | May 21, 2020 | An elevation of privilege vulnerability exists in Windows Installer because of the way Windows Installer handles certain filesystem operations. To exploit the vulnerability, an attacker would require unprivileged execution on the victim system. After successfully exploiting the… | ||
| CVE-2020-0843 | Hig | 0.51 | 7.8 | 0.01 | Mar 12, 2020 | An elevation of privilege vulnerability exists in Windows Installer because of the way Windows Installer handles certain filesystem operations.To exploit the vulnerability, an attacker would require unprivileged execution on the victim system, aka 'Windows Installer Elevation of… | ||
| CVE-2020-0842 | Hig | 0.51 | 7.8 | 0.01 | Mar 12, 2020 | An elevation of privilege vulnerability exists in Windows Installer because of the way Windows Installer handles certain filesystem operations.To exploit the vulnerability, an attacker would require unprivileged execution on the victim system, aka 'Windows Installer Elevation of… | ||
| CVE-2020-0814 | Hig | 0.51 | 7.8 | 0.01 | Mar 12, 2020 | An elevation of privilege vulnerability exists in Windows Installer because of the way Windows Installer handles certain filesystem operations.To exploit the vulnerability, an attacker would require unprivileged execution on the victim system, aka 'Windows Installer Elevation of… | ||
| CVE-2020-0798 | Hig | 0.51 | 7.8 | 0.01 | Mar 12, 2020 | An elevation of privilege vulnerability exists in the Windows Installer when the Windows Installer fails to properly sanitize input leading to an insecure library loading behavior.A locally authenticated attacker could run arbitrary code with elevated system privileges, aka… | ||
| CVE-2020-0686 | Hig | 0.51 | 7.8 | 0.01 | Feb 11, 2020 | An elevation of privilege vulnerability exists in the Windows Installer when MSI packages process symbolic links, aka 'Windows Installer Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0683. | ||
| CVE-2019-1415 | Hig | 0.51 | 7.8 | 0.01 | Nov 12, 2019 | An elevation of privilege vulnerability exists in Windows Installer because of the way Windows Installer handles certain filesystem operations.To exploit the vulnerability, an attacker would require unprivileged execution on the victim system, aka 'Windows Installer Elevation of… | ||
| CVE-2019-0973 | Hig | 0.51 | 7.8 | 0.01 | Jun 12, 2019 | An elevation of privilege vulnerability exists in the Windows Installer when the Windows Installer fails to properly sanitize input leading to an insecure library loading behavior. A locally authenticated attacker could run arbitrary code with elevated system privileges. An… | ||
| CVE-2016-7292 | Hig | 0.51 | 7.8 | 0.02 | Dec 20, 2016 | The Installer in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 mishandles library loading, which allows local users to gain… | ||
| CVE-2025-21331 | Hig | 0.48 | 7.3 | 0.01 | Jan 14, 2025 | Windows Installer Elevation of Privilege Vulnerability | ||
| CVE-2026-77894 | Hig | 0.46 | 7.0 | 0.00 | Sep 8, 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Installer allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-62694 | Hig | 0.46 | 7.0 | 0.00 | Sep 8, 2026 | Use after free in Windows Installer allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-61938 | Hig | 0.46 | 7.0 | 0.00 | Aug 11, 2026 | Use after free in Windows Installer allows an authorized attacker to elevate privileges locally. | ||
| CVE-2023-32050 | Hig | 0.46 | 7.0 | 0.00 | Jul 11, 2023 | Windows Installer Elevation of Privilege Vulnerability | ||
| CVE-2023-24904 | Hig | 0.46 | 7.1 | 0.01 | May 9, 2023 | Windows Installer Elevation of Privilege Vulnerability | ||
| CVE-2023-21542 | Hig | 0.46 | 7.0 | 0.00 | Jan 10, 2023 | Windows Installer Elevation of Privilege Vulnerability | ||
| CVE-2021-28440 | Hig | 0.46 | 7.0 | 0.01 | Apr 13, 2021 | Windows Installer Elevation of Privilege Vulnerability | ||
| CVE-2021-26862 | Hig | 0.46 | 7.0 | 0.01 | Mar 11, 2021 | Windows Installer Elevation of Privilege Vulnerability | ||
| CVE-2018-8339 | Hig | 0.46 | 7.0 | 0.02 | Aug 15, 2018 | An elevation of privilege vulnerability exists in the Windows Installer when the Windows Installer fails to properly sanitize input leading to an insecure library loading behavior, aka "Windows Installer Elevation of Privilege Vulnerability." This affects Windows 7, Windows… | ||
| CVE-2018-0868 | Hig | 0.46 | 7.0 | 0.02 | Mar 14, 2018 | Windows Installer in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016 and Windows Server, version 1709 allows an elevation of privilege vulnerability… |
- risk 0.51cvss 7.8epss 0.01
An elevation of privilege vulnerability exists in Windows Installer because of the way Windows Installer handles certain filesystem operations. To exploit the vulnerability, an attacker would require unprivileged execution on the victim system. After successfully exploiting the…
- risk 0.51cvss 7.8epss 0.01
An elevation of privilege vulnerability exists in Windows Installer because of the way Windows Installer handles certain filesystem operations.To exploit the vulnerability, an attacker would require unprivileged execution on the victim system, aka 'Windows Installer Elevation of…
- risk 0.51cvss 7.8epss 0.01
An elevation of privilege vulnerability exists in Windows Installer because of the way Windows Installer handles certain filesystem operations.To exploit the vulnerability, an attacker would require unprivileged execution on the victim system, aka 'Windows Installer Elevation of…
- risk 0.51cvss 7.8epss 0.01
An elevation of privilege vulnerability exists in Windows Installer because of the way Windows Installer handles certain filesystem operations.To exploit the vulnerability, an attacker would require unprivileged execution on the victim system, aka 'Windows Installer Elevation of…
- risk 0.51cvss 7.8epss 0.01
An elevation of privilege vulnerability exists in the Windows Installer when the Windows Installer fails to properly sanitize input leading to an insecure library loading behavior.A locally authenticated attacker could run arbitrary code with elevated system privileges, aka…
- risk 0.51cvss 7.8epss 0.01
An elevation of privilege vulnerability exists in the Windows Installer when MSI packages process symbolic links, aka 'Windows Installer Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0683.
- risk 0.51cvss 7.8epss 0.01
An elevation of privilege vulnerability exists in Windows Installer because of the way Windows Installer handles certain filesystem operations.To exploit the vulnerability, an attacker would require unprivileged execution on the victim system, aka 'Windows Installer Elevation of…
- risk 0.51cvss 7.8epss 0.01
An elevation of privilege vulnerability exists in the Windows Installer when the Windows Installer fails to properly sanitize input leading to an insecure library loading behavior. A locally authenticated attacker could run arbitrary code with elevated system privileges. An…
- risk 0.51cvss 7.8epss 0.02
The Installer in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 mishandles library loading, which allows local users to gain…
- risk 0.48cvss 7.3epss 0.01
Windows Installer Elevation of Privilege Vulnerability
- risk 0.46cvss 7.0epss 0.00
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Installer allows an authorized attacker to elevate privileges locally.
- risk 0.46cvss 7.0epss 0.00
Use after free in Windows Installer allows an authorized attacker to elevate privileges locally.
- risk 0.46cvss 7.0epss 0.00
Use after free in Windows Installer allows an authorized attacker to elevate privileges locally.
- risk 0.46cvss 7.0epss 0.00
Windows Installer Elevation of Privilege Vulnerability
- risk 0.46cvss 7.1epss 0.01
Windows Installer Elevation of Privilege Vulnerability
- risk 0.46cvss 7.0epss 0.00
Windows Installer Elevation of Privilege Vulnerability
- risk 0.46cvss 7.0epss 0.01
Windows Installer Elevation of Privilege Vulnerability
- risk 0.46cvss 7.0epss 0.01
Windows Installer Elevation of Privilege Vulnerability
- risk 0.46cvss 7.0epss 0.02
An elevation of privilege vulnerability exists in the Windows Installer when the Windows Installer fails to properly sanitize input leading to an insecure library loading behavior, aka "Windows Installer Elevation of Privilege Vulnerability." This affects Windows 7, Windows…
- risk 0.46cvss 7.0epss 0.02
Windows Installer in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016 and Windows Server, version 1709 allows an elevation of privilege vulnerability…
Page 3 of 4