CVE-2021-32415: High severity MSI Wrapper vulnerability
EXEMSI MSI Wrapper Versions prior to 10.0.50 and at least since version 6.0.91 will introduce a local privilege escalation vulnerability in installers it creates.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
EXEMSI MSI Wrapperto a version that resolves this vulnerability.Fixed in 10.0.50 - Compensating control
For installers created by EXEMSI MSI Wrapper versions prior to 10.0.50 (including at least since 6.0.91), treat them as vulnerable until upgraded; restrict execution of these installers to trusted users/hosts and validate the source before running.
Event History
Frequently Asked Questions
What is the severity of CVE-2021-32415?
CVE-2021-32415 has been issued a medium severity rating due to its local privilege escalation risk.
How do I fix CVE-2021-32415?
To mitigate CVE-2021-32415, upgrade to MSI Wrapper version 10.0.50 or later.
What versions are affected by CVE-2021-32415?
CVE-2021-32415 affects MSI Wrapper versions from 6.0.91 up to but not including 10.0.50.
Who is impacted by CVE-2021-32415?
Any user or organization using the affected versions of MSI Wrapper is at risk from CVE-2021-32415.
What type of vulnerability is CVE-2021-32415?
CVE-2021-32415 is a local privilege escalation vulnerability found in certain versions of MSI Wrapper.