CVE-2023-29080: Privilege escalation in InstallShield
Potential privilege escalation vulnerability in Revenera InstallShield versions 2022 R2 and 2021 R2 due to adding InstallScript custom action to a Basic MSI or InstallScript MSI project extracting few binaries to a predefined writable folder during installation time. The standard user account has write access to these files and folders, hence replacing them during installation time can lead to a DLL hijacking vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-29080?
CVE-2023-29080 is classified as a potential privilege escalation vulnerability.
Who is affected by CVE-2023-29080?
CVE-2023-29080 affects Revenera InstallShield versions 2022 R2 and 2021 R2.
How do I fix CVE-2023-29080?
To mitigate CVE-2023-29080, users should apply the security patch provided by Revenera.
What types of projects are vulnerable in CVE-2023-29080?
CVS-2023-29080 impacts Basic MSI and InstallScript MSI projects that utilize InstallScript custom actions.
What is the cause of CVE-2023-29080?
CVE-2023-29080 is caused by the extraction of binaries to a predefined writable folder during the installation process.