{ "id": "CVE-2021-41526", "sourceIdentifier": "PSIRT-CNA@flexerasoftware.com", "published": "2023-03-29T21:15:07.810", "lastModified": "2023-04-06T19:34:36.923", "vulnStatus": "Analyzed", "descriptions": [ { "lang": "en", "value": "A vulnerability has been reported in the windows installer (MSI) built with InstallScript custom action. This vulnerability may allow privilege escalation when invoked \u2018repair\u2019 of the MSI which has an InstallScript custom action." } ], "metrics": { "cvssMetricV31": [ { "source": "nvd@nist.gov", "type": "Primary", "cvssData": { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH" }, "exploitabilityScore": 1.8, "impactScore": 5.9 } ] }, "weaknesses": [ { "source": "nvd@nist.gov", "type": "Primary", "description": [ { "lang": "en", "value": "NVD-CWE-noinfo" } ] } ], "configurations": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:a:flexera:revenera_installshield:*:*:*:*:*:windows:*:*", "versionEndExcluding": "2021", "matchCriteriaId": "ED638412-2AD6-4860-9B87-C863984346AA" }, { "vulnerable": true, "criteria": "cpe:2.3:a:flexera:revenera_installshield:2021:-:*:*:*:windows:*:*", "matchCriteriaId": "08F8E0A6-92A1-4F49-B9C8-1698858587F4" }, { "vulnerable": true, "criteria": "cpe:2.3:a:flexera:revenera_installshield:2021:r1:*:*:*:windows:*:*", "matchCriteriaId": "7396B001-F8E1-48FB-AF78-E2FA8D81D662" } ] } ] } ], "references": [ { "url": "https://community.flexera.com/t5/InstallShield-Knowledge-Base/CVE-2021-41526-Privilege-escalation-vulnerability-during-MSI/ta-p/218137/jump-to/first-unread-message", "source": "PSIRT-CNA@flexerasoftware.com", "tags": [ "Vendor Advisory" ] }, { "url": "https://github.com/mandiant/Vulnerability-Disclosures/blob/master/MNDT-2021-0011/MNDT-2021-0011.md", "source": "PSIRT-CNA@flexerasoftware.com", "tags": [ "Third Party Advisory" ] } ] }