7.8
CVSSv3

CVE-2021-41526

Published: 29/03/2023 Updated: 19/04/2024
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 0

Vulnerability Summary

A vulnerability has been reported in the windows installer (MSI) built with InstallScript custom action. This vulnerability may allow privilege escalation when invoked ‘repair’ of the MSI which has an InstallScript custom action.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

flexera revenera installshield 2021

flexera revenera installshield

Mailing Lists

<!--X-Body-Begin--> <!--X-User-Header--> Full Disclosure mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> MindManager 23 - full disclosure <!--X-Subject-Header-End--> <!--X-Head-of-Message--> From: Pawel Karwowski via Full ...

Github Repositories

public disclosure

mindmanager-poc public disclosure: Affected application: MindManager23_setupexe Platform: Windows Issue: Local Privilege Escalation via MSI installer Repair Mode (EXE hijacking race condition) Discovered and reported by: Pawel Karwowski and Julian Horoszkiewicz (Eviden Red Team) Proposed mitigation: learnmicrosoftcom/en-us/windows/win32/msi/disablemsi Reasoning for p