René Helmke 7791f18b51 bootstrap
2023-05-16 16:09:41 +02:00

93 lines
2.8 KiB
JSON

{
"id": "CVE-2021-41526",
"sourceIdentifier": "PSIRT-CNA@flexerasoftware.com",
"published": "2023-03-29T21:15:07.810",
"lastModified": "2023-04-06T19:34:36.923",
"vulnStatus": "Analyzed",
"descriptions": [
{
"lang": "en",
"value": "A vulnerability has been reported in the windows installer (MSI) built with InstallScript custom action. This vulnerability may allow privilege escalation when invoked \u2018repair\u2019 of the MSI which has an InstallScript custom action."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"attackVector": "LOCAL",
"attackComplexity": "LOW",
"privilegesRequired": "LOW",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"availabilityImpact": "HIGH",
"baseScore": 7.8,
"baseSeverity": "HIGH"
},
"exploitabilityScore": 1.8,
"impactScore": 5.9
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "NVD-CWE-noinfo"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:flexera:revenera_installshield:*:*:*:*:*:windows:*:*",
"versionEndExcluding": "2021",
"matchCriteriaId": "ED638412-2AD6-4860-9B87-C863984346AA"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:flexera:revenera_installshield:2021:-:*:*:*:windows:*:*",
"matchCriteriaId": "08F8E0A6-92A1-4F49-B9C8-1698858587F4"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:flexera:revenera_installshield:2021:r1:*:*:*:windows:*:*",
"matchCriteriaId": "7396B001-F8E1-48FB-AF78-E2FA8D81D662"
}
]
}
]
}
],
"references": [
{
"url": "https://community.flexera.com/t5/InstallShield-Knowledge-Base/CVE-2021-41526-Privilege-escalation-vulnerability-during-MSI/ta-p/218137/jump-to/first-unread-message",
"source": "PSIRT-CNA@flexerasoftware.com",
"tags": [
"Vendor Advisory"
]
},
{
"url": "https://github.com/mandiant/Vulnerability-Disclosures/blob/master/MNDT-2021-0011/MNDT-2021-0011.md",
"source": "PSIRT-CNA@flexerasoftware.com",
"tags": [
"Third Party Advisory"
]
}
]
}