CVE-2020-0683 is an elevation of privilege vulnerability in the Windows Installer (msiexec.exe) that arises when MSI packages process symbolic links. The vulnerability allows a local attacker to exploit a race condition by creating symbolic links (such as directory junctions or object manager symlinks) in user-writable locations. When the Windows Installer, running with elevated privileges, performs file operations on these locations, the attacker can redirect these operations to arbitrary files or directories, potentially leading to privilege escalation or information disclosure. The vulnerability is distinct from CVE-2020-0686 and is part of a class of symlink-based attacks that abuse improper impersonation or security checks in privileged processes.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository contains a proof-of-concept (PoC) exploit for CVE-2020-0683, a Windows Installer Elevation of Privilege vulnerability. The exploit is implemented in C++ and is designed to be built with Visual Studio 2017. The main exploit logic resides in 'src_MsiExploit/MsiExploit/MsiExploit.cpp', which orchestrates the attack by manipulating NTFS reparse points (mount points and symbolic links) and abusing the Windows Installer service to gain write access to an arbitrary file specified by the attacker. The exploit requires a crafted MSI file ('foo.msi') and targets local privilege escalation on unpatched Windows systems. The repository includes utility code for file and directory operations, reparse point manipulation, and privilege adjustments. A batch script ('runExploit.bat') is provided to automate repeated exploitation attempts. The exploit does not provide a remote shell or user creation, but rather enables the attacker to overwrite or take ownership of a file, which can be leveraged for privilege escalation. The attack vector is local, requiring the attacker to execute code on the target system. The repository is well-structured, with clear separation between utility code and exploit logic.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.