Show filters
7 Total Results
Displaying 1-7 of 7
Sort by:
Attacker Value
Unknown
CVE-2023-29080
Disclosure Date: January 30, 2025 (last updated January 31, 2025)
Potential privilege escalation vulnerability in Revenera InstallShield versions 2022 R2 and 2021 R2 due to adding InstallScript custom action to a Basic MSI or InstallScript MSI project extracting few binaries to a predefined writable folder during installation time. The standard user account has write access to these files and folders, hence replacing them during installation time can lead to a DLL hijacking vulnerability.
0
Attacker Value
Unknown
CVE-2023-29081
Disclosure Date: January 26, 2024 (last updated February 02, 2024)
A vulnerability has been reported in Suite Setups built with versions prior to InstallShield 2023 R2. This vulnerability may allow locally authenticated users to cause a Denial of Service (DoS) condition when handling move operations on local, temporary folders.
0
Attacker Value
Unknown
CVE-2021-41526
Disclosure Date: March 29, 2023 (last updated October 08, 2023)
A vulnerability has been reported in the windows installer (MSI) built with InstallScript custom action. This vulnerability may allow privilege escalation when invoked ‘repair’ of the MSI which has an InstallScript custom action.
0
Attacker Value
Unknown
CVE-2016-2542
Disclosure Date: February 24, 2016 (last updated November 25, 2024)
Untrusted search path vulnerability in Flexera InstallShield through 2015 SP1 allows local users to gain privileges via a Trojan horse DLL in the current working directory of a setup-launcher executable file.
0
Attacker Value
Unknown
CVE-2007-6744
Disclosure Date: January 19, 2012 (last updated October 04, 2023)
Flexera Macrovision InstallShield before 2008 sends a digital-signature password to an unintended application during certain signature operations involving .spc and .pvk files, which might allow local users to obtain sensitive information via unspecified vectors, related to an incorrect interaction between InstallShield and Signcode.exe.
0
Attacker Value
Unknown
CVE-2007-5661
Disclosure Date: April 04, 2008 (last updated October 04, 2023)
The Macrovision InstallShield InstallScript One-Click Install (OCI) ActiveX control 12.0 before SP2 does not validate the DLL files that are named as parameters to the control, which allows remote attackers to download arbitrary library code onto a client machine.
0
Attacker Value
Unknown
CVE-2007-5660
Disclosure Date: November 02, 2007 (last updated October 04, 2023)
Unspecified vulnerability in the Update Service ActiveX control in isusweb.dll before 6.0.100.65101 in MacroVision FLEXnet Connect and InstallShield 2008 allows remote attackers to execute arbitrary code via an unspecified "unsafe method," possibly involving a buffer overflow.
0