Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jgh6-r92w-wgcf

Опубликовано: 30 янв. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 8.5

Описание

Potential privilege escalation vulnerability in Revenera InstallShield versions 2022 R2 and 2021 R2 due to adding InstallScript custom action to a Basic MSI or InstallScript MSI project extracting few binaries to a predefined writable folder during installation time. The standard user account has write access to these files and folders, hence replacing them during installation time can lead to a DLL hijacking vulnerability.

Potential privilege escalation vulnerability in Revenera InstallShield versions 2022 R2 and 2021 R2 due to adding InstallScript custom action to a Basic MSI or InstallScript MSI project extracting few binaries to a predefined writable folder during installation time. The standard user account has write access to these files and folders, hence replacing them during installation time can lead to a DLL hijacking vulnerability.

EPSS

Процентиль: 12%
0.00041
Низкий

8.5 High

CVSS4

Дефекты

CWE-552

Связанные уязвимости

nvd
около 1 года назад

Potential privilege escalation vulnerability in Revenera InstallShield versions 2022 R2 and 2021 R2 due to adding InstallScript custom action to a Basic MSI or InstallScript MSI project extracting few binaries to a predefined writable folder during installation time. The standard user account has write access to these files and folders, hence replacing them during installation time can lead to a DLL hijacking vulnerability.

EPSS

Процентиль: 12%
0.00041
Низкий

8.5 High

CVSS4

Дефекты

CWE-552