93 lines
2.8 KiB
JSON
Raw Normal View History

2023-04-24 12:24:31 +02:00
{
"id": "CVE-2021-41526",
"sourceIdentifier": "PSIRT-CNA@flexerasoftware.com",
"published": "2023-03-29T21:15:07.810",
"lastModified": "2023-04-06T19:34:36.923",
"vulnStatus": "Analyzed",
"descriptions": [
{
"lang": "en",
"value": "A vulnerability has been reported in the windows installer (MSI) built with InstallScript custom action. This vulnerability may allow privilege escalation when invoked \u2018repair\u2019 of the MSI which has an InstallScript custom action."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"attackVector": "LOCAL",
"attackComplexity": "LOW",
"privilegesRequired": "LOW",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"availabilityImpact": "HIGH",
"baseScore": 7.8,
"baseSeverity": "HIGH"
},
"exploitabilityScore": 1.8,
"impactScore": 5.9
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "NVD-CWE-noinfo"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:flexera:revenera_installshield:*:*:*:*:*:windows:*:*",
"versionEndExcluding": "2021",
"matchCriteriaId": "ED638412-2AD6-4860-9B87-C863984346AA"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:flexera:revenera_installshield:2021:-:*:*:*:windows:*:*",
"matchCriteriaId": "08F8E0A6-92A1-4F49-B9C8-1698858587F4"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:flexera:revenera_installshield:2021:r1:*:*:*:windows:*:*",
"matchCriteriaId": "7396B001-F8E1-48FB-AF78-E2FA8D81D662"
}
]
}
]
}
],
"references": [
{
"url": "https://community.flexera.com/t5/InstallShield-Knowledge-Base/CVE-2021-41526-Privilege-escalation-vulnerability-during-MSI/ta-p/218137/jump-to/first-unread-message",
"source": "PSIRT-CNA@flexerasoftware.com",
"tags": [
"Vendor Advisory"
]
},
{
"url": "https://github.com/mandiant/Vulnerability-Disclosures/blob/master/MNDT-2021-0011/MNDT-2021-0011.md",
"source": "PSIRT-CNA@flexerasoftware.com",
"tags": [
"Third Party Advisory"
]
}
]
}