First published: Wed Mar 29 2023(Updated: )
A vulnerability has been reported in the windows installer (MSI) built with InstallScript custom action. This vulnerability may allow privilege escalation when invoked ‘repair’ of the MSI which has an InstallScript custom action.
Credit: PSIRT-CNA@flexerasoftware.com PSIRT-CNA@flexerasoftware.com
Affected Software | Affected Version | How to fix |
---|---|---|
Flexera Revenera Installshield Windows | <2021 | |
Flexera Revenera Installshield Windows | =2021 | |
Flexera Revenera Installshield Windows | =2021-r1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-41526 is a vulnerability in the windows installer (MSI) built with InstallScript custom action that allows privilege escalation during the repair of the MSI.
CVE-2021-41526 affects Flexera Revenera Installshield versions 2021 and 2021-r1.
CVE-2021-41526 has a severity rating of 7.8 (high).
To fix CVE-2021-41526, it is recommended to update Flexera Revenera Installshield to the latest version available.
More information about CVE-2021-41526 can be found at the following references: [Link 1](https://community.flexera.com/t5/InstallShield-Knowledge-Base/CVE-2021-41526-Privilege-escalation-vulnerability-during-MSI/ta-p/218137/jump-to/first-unread-message), [Link 2](https://github.com/mandiant/Vulnerability-Disclosures/blob/master/MNDT-2021-0011/MNDT-2021-0011.md)