CVE-2023-29081: InstallShield Symlink Vulnerability Affecting Suite Project Setups

Published Jan 26, 2024
·
Updated

A vulnerability has been reported in Suite Setups built with versions prior to InstallShield 2023 R2. This vulnerability may allow locally authenticated users to cause a Denial of Service (DoS) condition when handling move operations on local, temporary folders.

Affected Software

20 affected components
Flexera InstallShield=2016
Flexera InstallShield=2016-sp1
Flexera InstallShield=2016-sp2
Flexera InstallShield=2017
Flexera InstallShield=2017-sp1
Flexera InstallShield=2018
Flexera InstallShield=2018-r2
Flexera InstallShield=2018-sp1
Flexera InstallShield=2019
Flexera InstallShield=2019-r2
Flexera InstallShield=2019-r3
Flexera InstallShield=2020
Flexera InstallShield=2020-r2
Flexera InstallShield=2020-r3
Flexera InstallShield=2020-r3sp1
Flexera InstallShield=2021-r1
Flexera InstallShield=2021-r2
Flexera InstallShield=2022-r1
Flexera InstallShield=2022-r2
Flexera InstallShield=2023-r1

Event History

Jan 26, 2024
CVE Published
via MITRE·08:02 PM
Data Sourced
via MITRE·08:02 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2023-29081?

CVE-2023-29081 is classified as a vulnerability that can lead to a Denial of Service (DoS) condition.

2

How do I fix CVE-2023-29081?

To fix CVE-2023-29081, users should update to InstallShield version 2023 R2 or later.

3

What types of systems are affected by CVE-2023-29081?

CVE-2023-29081 affects installations created with versions of InstallShield prior to 2023 R2.

4

Who can exploit the CVE-2023-29081 vulnerability?

CVE-2023-29081 can be exploited by locally authenticated users to trigger a DoS condition.

5

What are the potential impacts of CVE-2023-29081?

The potential impact of CVE-2023-29081 is a Denial of Service (DoS) when handling move operations on local temporary folders.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203