CVE-2024-14012: Potential Privilege Escalation in Revenera InstallShield 2023 R1
Potential privilege escalation issue in Revenera InstallShield version 2023 R1 running a renamed Setup.exe on Windows. When a local administrator executes a renamed Setup.exe, the MPR.dll may get loaded from an insecure location and can result in a privilege escalation. The issue has been fixed in versions 2023 R2 and later.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-14012?
CVE-2024-14012 is classified as a potential privilege escalation vulnerability.
How do I fix CVE-2024-14012?
To mitigate CVE-2024-14012, ensure that you do not rename the Setup.exe file and keep your Revenera InstallShield updated beyond version 2023 R2.
Which versions of Revenera InstallShield are affected by CVE-2024-14012?
CVE-2024-14012 affects Revenera InstallShield versions up to and including 2023 R1.
Can CVE-2024-14012 lead to unauthorized access?
Yes, CVE-2024-14012 can lead to unauthorized privilege escalation if exploited.
What triggers the vulnerability CVE-2024-14012?
CVE-2024-14012 is triggered when a local administrator executes a renamed Setup.exe, causing MPR.dll to load from an insecure location.