CVE-2020-16268
HIGH1E Client 4.1.0.267 and 5.0.0.745 - Authenticated Privilege Escalation via MSI Repair Option
Title source: llmDescription
The MSI installer in 1E Client 4.1.0.267 and 5.0.0.745 allows remote authenticated users and local users to gain elevated privileges via the repair option. This applies to installations that have a TRANSFORM (MST) with the option to disable the installation of the Nomad module. An attacker may craft a .reg file in a specific location that will be able to write to any registry key as an elevated user.
References (1)
Core 1
Core References
Scores
CVSS v3
8.8
EPSS
0.0132
EPSS Percentile
67.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-74
CWE-668
Status
published
Products (2)
1e/client
4.1.0.267
1e/client
5.0.0.745
Published
Dec 29, 2020
Tracked Since
Feb 18, 2026