Improper link resolution before file access ('link following') in Windows Installer allows an authorized attacker to disclose information locally.
No PoCs from references.
- https://github.com/ARPSyndicate/cve-scores