U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2019-0973

Change History

CVE Modified by Microsoft Corporation 5/20/2025 2:15:32 PM

Action Type Old Value New Value
Changed Description
An elevation of privilege vulnerability exists in the Windows Installer when the Windows Installer fails to properly sanitize input leading to an insecure library loading behavior.A locally authenticated attacker could run arbitrary code with elevated system privileges, aka 'Windows Installer Elevation of Privilege Vulnerability'.
An elevation of privilege vulnerability exists in the Windows Installer when the Windows Installer fails to properly sanitize input leading to an insecure library loading behavior.
A locally authenticated attacker could run arbitrary code with elevated system privileges. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
The security update addresses the vulnerability by correcting the input sanitization error to preclude unintended elevation.
Added CVSS V3.1

								
							
							
						
AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Added Reference

								
							
							
						
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2019-0973
Removed Reference
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0973

								
						
Removed Reference Type
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0973 Types: Patch, Vendor Advisory