Summary
A potential privilege escalation issue was identified in InstallShield version 2025 R2 and earlier when running compressed Basic MSI setup with Prerequisites from an insecure location. If a local administrator launches a compressed Setup.exe with Prerequisites from an unsecured location, the Prerequisite installers also might load from an unsecured location, potentially leading to privilege escalation.
Resolution
It is important to follow security best practices to avoid running installers especially with elevated, administrator privileges from insecure or untrusted directories. A patch to address this issue for InstallShield 2025 R2 is available for download from the Product and License Center. Patches for InstallShield supported versions (2024 R2 and 2023 R2) will be available tomorrow on the Product and License Center.
Additional Information
For identifying this vulnerability and disclosing it to Revenera under a responsible disclosure process, we'd like to thank and give credit to Sandeep Kumar Singh (AMD).
Related Articles
CVE-2023-29080: Security patch for the possible privileged escalation scenarios identified in InstallShield 11Number of Views CVE-2024-7562: Privilege Escalation Vulnerability in Created MSI Packages 127Number of Views CVE-2024-3310: Privilege Escalation Vulnerability During MSI Repair 6Number of Views CVE-2024-2658: FlexNet Publisher potential local privilege escalation issue 15Number of Views CVE-2024-14012: Potential Privilege Escalation in InstallShield 2023 R1 3Number of Views
Hi, I am Reva - Ask me anything.
No new updates
Thanks for the feedback!
Your feedback has been saved.Rate this response:
Add Additional feedback ( Optional )
Are you sure you want to cancel
the case creation?
Are you sure you want to cancel the case creation?
Are you sure you want to close this case
| Products | Region | Phone Numbers |
|---|---|---|
| FlexNet Operations FlexNet Embedded FlexNet Publisher FlexNet Connect FlexNet Code Insight InstallAnywhere InstallShield |
North America * |
+1 630-332-2513 (toll) +1 877-279-2853 (toll-free in North America) |
| Europe * |
+44 1925 944367 (toll) +44 800 047 8642 (toll-free in Europe) |
|
| Japan * | +81 3-4540-5335 (select option 2) | |
| Australia * |
+61 3 9895 2177 +61 1800 560 603 (toll-free in Australia) |
|
|
Usage Intelligence (formerly
Revulytics) Compliance Intelligence |
Please use the Case Portal to submit your support ticket or reach out to your Revenera contact. | |
Case id: 00001065
Activity: Status change: 2 hours ago