CVE-2021-22037: High severity vmware installbuilder vulnerability
Under certain circumstances, when manipulating the Windows registry, InstallBuilder uses the reg.exe system command. The full path to the command is not enforced, which results in a search in the search path until a binary can be identified. This makes the installer/uninstaller vulnerable to Path Interception by Search Order Hijacking, potentially allowing an attacker to plant a malicious reg.exe command so it takes precedence over the system command. The vulnerability only affects Windows installers.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-22037?
The severity of CVE-2021-22037 is classified as Medium, indicating potential security risks that may affect system integrity.
How do I mitigate CVE-2021-22037?
To mitigate CVE-2021-22037, ensure that you are using VMware InstallBuilder version 21.6.0 or later, as this version addresses the vulnerability.
What systems are affected by CVE-2021-22037?
CVE-2021-22037 affects VMware InstallBuilder versions prior to 21.6.0 installed on Windows operating systems.
Is CVE-2021-22037 exploitable remotely?
CVE-2021-22037 is not considered remotely exploitable as it requires local access to the affected installer/uninstaller.
What happens if I do not address CVE-2021-22037?
Failure to address CVE-2021-22037 may result in unauthorized manipulation of the Windows registry, potentially leading to system compromise.