Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-32683 | Potential privilege escalation vulnerability in Revenera InstallShield versions 2022 R2 and 2021 R2 due to adding InstallScript custom action to a Basic MSI or InstallScript MSI project extracting few binaries to a predefined writable folder during installation time. The standard user account has write access to these files and folders, hence replacing them during installation time can lead to a DLL hijacking vulnerability. |
Wed, 12 Feb 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 30 Jan 2025 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Potential privilege escalation vulnerability in Revenera InstallShield versions 2022 R2 and 2021 R2 due to adding InstallScript custom action to a Basic MSI or InstallScript MSI project extracting few binaries to a predefined writable folder during installation time. The standard user account has write access to these files and folders, hence replacing them during installation time can lead to a DLL hijacking vulnerability. | |
| Title | Privilege escalation in InstallShield | |
| Weaknesses | CWE-552 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: flexera
Published:
Updated: 2025-02-12T17:03:46.935Z
Reserved: 2023-03-30T23:42:11.691Z
Link: CVE-2023-29080
Updated: 2025-02-12T17:03:12.847Z
Status : Deferred
Published: 2025-01-30T18:15:28.437
Modified: 2026-04-15T00:35:42.020
Link: CVE-2023-29080
No data.
OpenCVE Enrichment
Updated: 2025-07-13T11:23:03Z
EUVD