CVE-2016-2542: High severity aveva edge vulnerability
Untrusted search path vulnerability in Flexera InstallShield through 2015 SP1 allows local users to gain privileges via a Trojan horse DLL in the current working directory of a setup-launcher executable file.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2016-2542?
CVE-2016-2542 is considered a high severity vulnerability due to its potential for privilege escalation.
How do I fix CVE-2016-2542?
To fix CVE-2016-2542, ensure that the setup-launcher executable is executed in a secure directory free from untrusted DLL files.
Who is affected by CVE-2016-2542?
CVE-2016-2542 affects users of Flexera InstallShield through 2015 SP1 and various products that integrate InstallShield, including AVEVA Edge 2020 R2 and prior versions.
What are the consequences of exploiting CVE-2016-2542?
Exploitation of CVE-2016-2542 can lead to local users gaining elevated privileges on the affected system.
Is there a workaround for CVE-2016-2542?
A possible workaround for CVE-2016-2542 is to implement strict folder permission settings to prevent unauthorized access to the current working directory.