First published: Fri May 06 2022(Updated: )
The BigFix Client installer is created with InstallShield, which was affected by CVE-2021-41526, a vulnerability that could allow a local user to perform a privilege escalation. This vulnerability was resolved by updating to an InstallShield version with the underlying vulnerability fixed.
Credit: psirt@hcl.com
Affected Software | Affected Version | How to fix |
---|---|---|
Hcltech Bigfix Platform | >=9.5<=9.5.18 | |
Hcltech Bigfix Platform | >=10<=10.0.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-27766 is a vulnerability affecting the BigFix Client installer, created with InstallShield, that could allow a local user to perform privilege escalation.
CVE-2021-27766 affects Hcltech Bigfix Platform versions 9.5 to 9.5.18 and versions 10 to 10.0.5, potentially allowing local users to perform privilege escalation.
CVE-2021-27766 has a severity rating of 7.8 (high).
To fix CVE-2021-27766, update the BigFix Client installer to a version that includes the fix for the underlying vulnerability in InstallShield.
More information about CVE-2021-27766 can be found in the vulnerability disclosures document: https://github.com/mandiant/Vulnerability-Disclosures/blob/master/2022/MNDT-2022-0024/MNDT-2022-0024.md and the Hcltech support article: https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0098116.