CVE-2021-41526: High severity flexera installshield vulnerability
A vulnerability has been reported in the windows installer (MSI) built with InstallScript custom action. This vulnerability may allow privilege escalation when invoked ‘repair’ of the MSI which has an InstallScript custom action.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-41526?
CVE-2021-41526 is a vulnerability in the windows installer (MSI) built with InstallScript custom action that allows privilege escalation during the repair of the MSI.
How does CVE-2021-41526 affect Flexera Revenera Installshield?
CVE-2021-41526 affects Flexera Revenera Installshield versions 2021 and 2021-r1.
What is the severity of CVE-2021-41526?
CVE-2021-41526 has a severity rating of 7.8 (high).
How can I fix CVE-2021-41526?
To fix CVE-2021-41526, it is recommended to update Flexera Revenera Installshield to the latest version available.
Where can I find more information about CVE-2021-41526?
More information about CVE-2021-41526 can be found at the following references: [Link 1](https://community.flexera.com/t5/InstallShield-Knowledge-Base/CVE-2021-41526-Privilege-escalation-vulnerability-during-MSI/ta-p/218137/jump-to/first-unread-message), [Link 2](https://github.com/mandiant/Vulnerability-Disclosures/blob/master/MNDT-2021-0011/MNDT-2021-0011.md)