CVE-2021-27766: HCL BigFix Platform Client is affected by a Privilege Escalation Vulnerability
The BigFix Client installer is created with InstallShield, which was affected by CVE-2021-41526, a vulnerability that could allow a local user to perform a privilege escalation. This vulnerability was resolved by updating to an InstallShield version with the underlying vulnerability fixed.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-27766?
CVE-2021-27766 is a vulnerability affecting the BigFix Client installer, created with InstallShield, that could allow a local user to perform privilege escalation.
How does CVE-2021-27766 impact Hcltech Bigfix Platform?
CVE-2021-27766 affects Hcltech Bigfix Platform versions 9.5 to 9.5.18 and versions 10 to 10.0.5, potentially allowing local users to perform privilege escalation.
What is the severity of CVE-2021-27766?
CVE-2021-27766 has a severity rating of 7.8 (high).
How can I fix CVE-2021-27766?
To fix CVE-2021-27766, update the BigFix Client installer to a version that includes the fix for the underlying vulnerability in InstallShield.
Where can I find more information about CVE-2021-27766?
More information about CVE-2021-27766 can be found in the vulnerability disclosures document: https://github.com/mandiant/Vulnerability-Disclosures/blob/master/2022/MNDT-2022-0024/MNDT-2022-0024.md and the Hcltech support article: https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0098116.