First published: Sat Jul 02 2016(Updated: )
Untrusted search path vulnerability in Flexera InstallAnywhere allows local users to gain privileges via a Trojan horse DLL in the current working directory of a setup-launcher executable file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zero G InstallAnywhere |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-4560 has been classified as a high severity vulnerability due to its potential to grant local users increased privileges.
To mitigate CVE-2016-4560, ensure that the working directory for setup executables does not contain untrusted DLLs.
CVE-2016-4560 affects users of Flexera InstallAnywhere who are running installations with setup-launcher executables.
CVE-2016-4560 is an untrusted search path vulnerability that allows the execution of malicious DLLs.
CVE-2016-4560 requires local access to exploit, as it targets the working directory of a local installation process.