{"id":"CVE-2019-16784","aliases":["GHSA-7fcj-pq9j-wh2r","PYSEC-2020-175"],"title":"Local Privilege Escalation in PyInstaller","summary":"Local Privilege Escalation in PyInstaller","severity":"high","cvss":7,"cvssVector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","vendor":"pyinstaller","product":"pyinstaller","ecosystem":"pip","affected":["pyinstaller < 3.6"],"patched":["pyinstaller 3.6"],"published":"2020-01-16","updated":"2026-09-10","sourceUpdated":"2026-09-10T03:49:25.186628514Z","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-7fcj-pq9j-wh2r","references":[{"url":"https://github.com/pyinstaller/pyinstaller/security/advisories/GHSA-7fcj-pq9j-wh2r"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2019-16784"},{"url":"https://github.com/pyinstaller/pyinstaller/commit/42a67148b3bdf9211fda8499fdc5b63acdd7e6cc"},{"url":"https://github.com/pyinstaller/pyinstaller/commit/be948cf0954707671aa499da17b10c86b6fa5e5c"},{"url":"https://github.com/pyinstaller/pyinstaller"},{"url":"https://github.com/pypa/advisory-database/tree/main/vulns/pyinstaller/PYSEC-2020-175.yaml"}],"tags":["osv","pip","exploit-available"],"epss":0.00695,"epssPercentile":0.51137,"exploits":{"github":2,"githubRepos":["https://github.com/AlterSolutions/PyInstallerPrivEsc","https://github.com/Ckrielle/CVE-2019-16784-POC"],"checkedAt":"2026-09-21T15:23:43.349Z"},"exploitAvailable":true,"ingestedAt":"2026-09-12T03:13:01.671Z","slug":"CVE-2019-16784","body":"## Overview\n\n### Impact\n\nLocal Privilege Escalation in all Windows software frozen by PyInstaller in \"onefile\" mode.\n\nThe vulnerability is present only on Windows and in this particular case: If a **software frozen by PyInstaller in \"onefile\" mode** is launched by a (privileged) user who has **his/her \"TempPath\" resolving to a world writable directory**. This is the case e.g. if the software is launched as a service or as a scheduled task using a system account (in which case TempPath will default to C:\\Windows\\Temp).\n\nIn order to be exploitable the software has to be (re)started after the attacker has launched the exploit program. So for a service launched at startup, a service restart is needed (e.g. after a crash or an upgrade).\n\nWhile PyInstaller itself was not vulnerable, all Windows software frozen by PyInstaller in \"onefile\" mode is vulnerable.\n\nCVSSv3 score 7.0 (High)\nCVSSv3 vector CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H\n\nAffected\n- all Windows software frozen by PyInstaller in \"onefile\" mode\n\nNo affected\n- PyInstaller itself (except if frozen by PyInstaller in \"onefile\" mode on Windows)\n- software frozen in \"one*dir*\" mode\n- other platforms (GNU/Linux, OS X, BSD, etc.)\n\n### Patches\nThe problem is patched in commits 42a67148b3bdf9211fda8499fdc5b63acdd7e6cc (fixed code) and be948cf0954707671aa499da17b10c86b6fa5e5c (recompiled bootloaders). Users should upgrade to PyInstaller version 3.6 and rebuild their software.\n\n### Workarounds\nThere is no known workaround. Users using PyInstaller to freeze their Windows software using \"onefile\" mode should upgrade PyInstaller and rebuild their software.\n\n### Credits\nThis vulnerability was discovered and reported by Farid AYOUJIL (@faridtsl), David HA, Florent LE NIGER and Yann GASCUEL (@lnv42) from Alter Solutions (@AlterSolutions) and fixed in collaboration with\nHartmut Goebel (@htgoebel, maintainer of PyInstaller).\n\n### Funding Development\n\nPyInstaller is in urgent need of funding to make future security fixes happen, see <https://github.com/pyinstaller/pyinstaller/issues/4404> for details.\n\n## Affected packages\n\n- `pyinstaller < 3.6`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `pyinstaller 3.6`","depth":"midnight","depthScore":51,"depthScoreParts":{"impact":38.5,"likelihood":0.1,"exploitation":12,"ransomware":0},"changes":[]}