First published: Wed Feb 24 2016(Updated: )
Untrusted search path vulnerability in Flexera InstallShield through 2015 SP1 allows local users to gain privileges via a Trojan horse DLL in the current working directory of a setup-launcher executable file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
AVEVA Edge | ||
AVEVA Edge 2020 R2 SP1 | ||
AVEVA InduSoft Web Studio | ||
Flexera InstallShield | ||
Flexera InstallShield | ||
InstallShield | <2015 | |
InstallShield | =2015 | |
InstallShield | =2015-sp1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-2542 is considered a high severity vulnerability due to its potential for privilege escalation.
To fix CVE-2016-2542, ensure that the setup-launcher executable is executed in a secure directory free from untrusted DLL files.
CVE-2016-2542 affects users of Flexera InstallShield through 2015 SP1 and various products that integrate InstallShield, including AVEVA Edge 2020 R2 and prior versions.
Exploitation of CVE-2016-2542 can lead to local users gaining elevated privileges on the affected system.
A possible workaround for CVE-2016-2542 is to implement strict folder permission settings to prevent unauthorized access to the current working directory.