A vulnerability has been reported in the windows installer (MSI) built with InstallScript custom action. This vulnerability may allow privilege escalation when invoked ‘repair’ of the MSI which has an InstallScript custom action.
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 06:26
Type | Values Removed | Values Added |
---|---|---|
References | () http://seclists.org/fulldisclosure/2024/Apr/24 - | |
References | () https://community.flexera.com/t5/InstallShield-Knowledge-Base/CVE-2021-41526-Privilege-escalation-vulnerability-during-MSI/ta-p/218137/jump-to/first-unread-message - Vendor Advisory | |
References | () https://github.com/mandiant/Vulnerability-Disclosures/blob/master/MNDT-2021-0011/MNDT-2021-0011.md - Third Party Advisory |
19 Apr 2024, 15:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
Information
Published : 2023-03-29 21:15
Updated : 2024-11-21 06:26
NVD link : CVE-2021-41526
Mitre link : CVE-2021-41526
CVE.ORG link : CVE-2021-41526
JSON object : View
Products Affected
flexera
- revenera_installshield
CWE