vulnerability
Microsoft Windows: CVE-2019-0973: Windows Installer Elevation of Privilege Vulnerability
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 7 | (AV:L/AC:L/Au:N/C:C/I:C/A:C) | Jun 11, 2019 | Jun 11, 2019 | Sep 5, 2025 |
Severity
7
CVSS
(AV:L/AC:L/Au:N/C:C/I:C/A:C)
Published
Jun 11, 2019
Added
Jun 11, 2019
Modified
Sep 5, 2025
Description
An elevation of privilege vulnerability exists in the Windows Installer when the Windows Installer fails to properly sanitize input leading to an insecure library loading behavior.A locally authenticated attacker could run arbitrary code with elevated system privileges, aka 'Windows Installer Elevation of Privilege Vulnerability'.
Solutions
microsoft-windows-windows_10-1507-kb4503291microsoft-windows-windows_10-1607-kb4503267microsoft-windows-windows_10-1703-kb4503279microsoft-windows-windows_10-1709-kb4503284microsoft-windows-windows_10-1803-kb4503286microsoft-windows-windows_10-1809-kb4503327microsoft-windows-windows_10-1903-kb4503293microsoft-windows-windows_server_2012-kb4503263microsoft-windows-windows_server_2012_r2-kb4503290microsoft-windows-windows_server_2016-1607-kb4503267microsoft-windows-windows_server_2019-1809-kb4503327msft-kb4503263-3f49e638-6f8c-47cd-a1cd-255c6ae917bamsft-kb4503263-bce6e093-7a69-4f5b-9b2a-c4861df34e7bmsft-kb4503269-1cdbe639-c27c-4ac7-9343-f9bf1604f686msft-kb4503269-2ab80a73-82cd-43ce-a721-9bdf2efe53cbmsft-kb4503269-358b582d-4bc3-413a-8b92-8bcf4353a820msft-kb4503269-3c4860d8-79ae-4d88-b2ea-5514f6cff025msft-kb4503269-48d42c58-c168-47e3-b5b9-fa8b78b0ae33msft-kb4503269-af9ce13b-08ae-4959-9ba1-cbfb91fb4189msft-kb4503287-847114ee-376d-46b7-b2cd-b00c06ebf72emsft-kb4503287-a3ab06bf-f665-4dbf-9f11-3a14c721ab1bmsft-kb4503287-ac203890-b63c-4698-993f-b654f3a37ae6msft-kb4503290-1a32764d-38ac-46c1-95fd-1bbb92147e05msft-kb4503290-b489422c-7cde-4048-b72d-6ba8cfeb9ea5msft-kb4503293-c6d3d33b-8eca-4003-9755-d7eb5e197ac7
References
NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.