For the convenience of customers and compliance with CNA guidelines, this post consolidates the CVEs applying to Revenera as of 2025-11-12. It does not contain CVEs for Flexera, which can be found within the Flexera Community site.
We plan to provide a new dedicated location to view all Flexera, Revenera, Snow Software, Spot. and Cloudcheckr CVEs in a single place at a later date.
Revenera Summary
- FlexNet Publisher: CVE-2024-2658, CVE-2019-8963, CVE-2020-12080, CVE-2019-8960, CVE-2019-8961, CVE-2018-20034, CVE-2018-20031, CVE-2018-20032, CVE-2018-20033, CVE-2016-10395, CVE-2017-5571, CVE-2015-8277, CVE-2011-4134, CVE-2011-4135
- InstallShield 2023: CVE-2025-12418, CVE-2024-7562, CVE-2024-3310, CVE-2024-14012, CVE-2023-29081
- InstallShield 2022: CVE-2024-7562, CVE-2024-3310, CVE-2023-29080
- InstallShield 2021: CVE-2024-7562, CVE-2024-3310, CVE-2023-29080, CVE-2021-41526
- InstallShield 2019, 2020: CVE-2021-41526
FlexNet Publisher
| CVE-2024-2658 | |
|---|---|
|
Secunia Advisory ID |
SA125662 |
|
Creation Date |
2024-04-02 |
|
Criticality |
Less critical |
|
Zero Day |
No |
|
Impact |
Privilege escalation |
|
Where |
Local system |
|
Solution Status |
Vendor Patched |
|
Secunia CVSS Scores |
CVSS3 Base: 7.8, Overall: 6.8 |
|
CVE References |
CVE-2024-2658 |
| CVE-2019-8963, CVE-2020-12080 | |
|---|---|
|
Secunia Advisory ID |
SA94747 |
|
Creation Date |
2020-04-28 |
|
Criticality |
Less critical |
|
Zero Day |
No |
|
Impact |
DoS |
|
Where |
From local network |
|
Solution Status |
Vendor Patched |
|
Secunia CVSS Scores |
CVSS3 Base: 6.5, Overall: 5.7 |
|
CVE References |
CVE-2019-8963, CVE-2020-12080 |
| CVE-2019-8960, CVE-2019-8961 | |
|---|---|
|
Secunia Advisory ID |
SA92282 |
|
Creation Date |
2019-11-22 |
|
Criticality |
Less critical |
|
Zero Day |
No |
|
Impact |
DoS |
|
Where |
From local network |
|
Solution Status |
Vendor Patched |
|
Secunia CVSS Scores |
CVSS3 Base: 6.5, Overall: 5.7 |
|
CVE References |
CVE-2019-8960, CVE-2019-8961 |
| CVE-2018-20034, CVE-2018-20031, CVE-2018-20032, CVE-2018-20033 | |
|---|---|
|
Secunia Advisory ID |
SA85979 |
|
Creation Date |
2019-01-29 |
|
Criticality |
Moderately critical |
|
Zero Day |
No |
|
Impact |
System access, DoS |
|
Where |
From local network |
|
Solution Status |
Vendor Patched |
|
Secunia CVSS Scores |
CVSS3 Base: 8.8, Overall: 7.9 |
|
CVE References |
CVE-2018-20034,CVE-2018-20031,CVE-2018-20032,CVE-2018-20033 |
| CVE-2016-10395 | |
|---|---|
|
Secunia Advisory ID |
SA76368 |
|
Creation Date |
2017-06-07 |
|
Criticality |
Less critical |
|
Zero Day |
No |
|
Impact |
Privilege escalation |
|
Where |
Local system |
|
Solution Status |
Vendor Patched |
|
Secunia CVSS Scores |
Base: 6.8, Overall: 5 |
|
CVE References |
CVE-2016-10395 |
| CVE-2017-5571 | |
|---|---|
|
Secunia Advisory ID |
SA75061 |
|
Creation Date |
2017-02-07 |
|
Criticality |
Not critical |
|
Zero Day |
No |
|
Impact |
Spoofing |
|
Where |
From remote |
|
Solution Status |
Vendor Workaround |
|
Secunia CVSS Scores |
Base: 4.3, Overall: 3.3 |
|
CVE References |
CVE-2017-5571 |
| CVE-2015-8277 | |
|---|---|
|
Secunia Advisory ID |
SA69145 |
|
Creation Date |
2016-02-23 |
|
Criticality |
Moderately critical |
|
Zero Day |
No |
|
Impact |
System access |
|
Where |
From local network |
|
Solution Status |
Vendor Patched |
|
Secunia CVSS Scores |
Base: 8.3, Overall: 6.1 |
|
CVE References |
CVE-2015-8277 |
| CVE-2011-4135 | |
|---|---|
|
Secunia Advisory ID |
SA45615 |
|
Creation Date |
2011-08-18 |
|
Criticality |
Moderately critical |
|
Zero Day |
No |
|
Impact |
System access |
|
Where |
From local network |
|
Solution Status |
Vendor Patched |
|
Secunia CVSS Scores |
Base: 8.3, Overall: 6.1 |
|
CVE References |
CVE-2011-4135 |
| CVE-2011-4134 | |
|---|---|
|
Secunia Advisory ID |
SA45397 |
|
Creation Date |
2011-08-04 |
|
Criticality |
Moderately critical |
|
Zero Day |
No |
|
Impact |
System access |
|
Where |
From local network |
|
Solution Status |
Vendor Patched |
|
Secunia CVSS Scores |
Base: 8.3, Overall: 5.8 |
|
CVE References |
CVE-2011-4134 |
InstallShield (2023)
| CVE-2025-12418 | |
|---|---|
|
Secunia Advisory ID |
SA147574 |
|
Creation Date |
2025-11-11 |
|
Criticality |
Not critical |
|
Zero Day |
No |
|
Impact |
DoS |
|
Where |
Local system |
|
Solution Status |
Vendor Patched |
|
Secunia CVSS Scores |
CVSS3 Base: 5.5, Overall: 4.8 |
|
CVE References |
CVE-2025-12418 |
| CVE-2024-7562 | |
|---|---|
|
Secunia Advisory ID |
SA140723 |
|
Creation Date |
2025-06-13 |
|
Criticality |
Less critical |
|
Zero Day |
No |
|
Impact |
Privilege escalation |
|
Where |
Local system |
|
Solution Status |
No Fix |
|
Secunia CVSS Scores |
CVSS3 Base: 7.8, Overall: 6.8 |
|
CVE References |
CVE-2024-7562 |
| CVE-2024-3310 | |
|---|---|
|
Secunia Advisory ID |
SA126024 |
|
Creation Date |
2024-04-17 |
|
Criticality |
Less critical |
|
Zero Day |
No |
|
Impact |
Privilege escalation |
|
Where |
Local system |
|
Solution Status |
Partial Fix |
|
Secunia CVSS Scores |
CVSS3 Base: 7.8, Overall: 6.9 |
|
CVE References |
CVE-2024-3310 |
| CVE-2024-14012, CVE-2023-29081 | |
|---|---|
|
Secunia Advisory ID |
SA123416 |
|
Creation Date |
2024-01-27 |
|
Criticality |
Less critical |
|
Zero Day |
No |
|
Impact |
DoS, Privilege escalation |
|
Where |
Local system |
|
Solution Status |
Vendor Patched |
|
Secunia CVSS Scores |
CVSS3 Base: 7.3, Overall: 6.4 |
|
CVE References |
CVE-2024-14012, CVE-2023-29081 |
InstallShield (2022)
| CVE-2024-7562 | |
|---|---|
|
Secunia Advisory ID |
SA140723 |
|
Creation Date |
2025-06-13 |
|
Criticality |
Less critical |
|
Zero Day |
No |
|
Impact |
Privilege escalation |
|
Where |
Local system |
|
Solution Status |
No Fix |
|
Secunia CVSS Scores |
CVSS3 Base: 7.8, Overall: 6.8 |
|
CVE References |
CVE-2024-7562 |
| CVE-2024-3310 | |
|---|---|
|
Secunia Advisory ID |
SA126024 |
|
Creation Date |
2024-04-17 |
|
Criticality |
Less critical |
|
Zero Day |
No |
|
Impact |
Privilege escalation |
|
Where |
Local system |
|
Solution Status |
Partial Fix |
|
Secunia CVSS Scores |
CVSS3 Base: 7.8, Overall: 6.9 |
|
CVE References |
CVE-2024-3310 |
| CVE-2023-29080 | |
|---|---|
|
Secunia Advisory ID |
SA115284 |
|
Creation Date |
2023-04-13 |
|
Criticality |
Less critical |
|
Zero Day |
No |
|
Impact |
Privilege escalation |
|
Where |
Local system |
|
Solution Status |
Vendor Patched |
|
Secunia CVSS Scores |
CVSS3 Base: 7.8, Overall: 6.8 |
|
CVE References |
CVE-2023-29080 |
InstallShield (2021)
| CVE-2024-7562 | |
|---|---|
|
Secunia Advisory ID |
SA140723 |
|
Creation Date |
2025-06-13 |
|
Criticality |
Less critical |
|
Zero Day |
No |
|
Impact |
Privilege escalation |
|
Where |
Local system |
|
Solution Status |
No Fix |
|
Secunia CVSS Scores |
CVSS3 Base: 7.8, Overall: 6.8 |
|
CVE References |
CVE-2024-7562 |
| CVE-2024-3310 | |
|---|---|
|
Secunia Advisory ID |
SA126024 |
|
Creation Date |
2024-04-17 |
|
Criticality |
Less critical |
|
Zero Day |
No |
|
Impact |
Privilege escalation |
|
Where |
Local system |
|
Solution Status |
Partial Fix |
|
Secunia CVSS Scores |
CVSS3 Base: 7.8, Overall: 6.9 |
|
CVE References |
CVE-2024-3310 |
| CVE-2023-29080 | |
|---|---|
|
Secunia Advisory ID |
SA115284 |
|
Creation Date |
2023-04-13 |
|
Criticality |
Less critical |
|
Zero Day |
No |
|
Impact |
Privilege escalation |
|
Where |
Local system |
|
Solution Status |
Vendor Patched |
|
Secunia CVSS Scores |
CVSS3 Base: 7.8, Overall: 6.8 |
|
CVE References |
CVE-2023-29080 |
| CVE-2021-41526 | |
|---|---|
|
Secunia Advisory ID |
SA105738 |
|
Creation Date |
2021-12-18 |
|
Criticality |
Less critical |
|
Zero Day |
No |
|
Impact |
Privilege escalation |
|
Where |
Local system |
|
Solution Status |
Vendor Patched |
|
Secunia CVSS Scores |
CVSS3 Base: 7.8, Overall: 6.8 |
|
CVE References |
CVE-2021-41526 |
InstallShield (2020, 2019)
| CVE-2021-41526 | |
|---|---|
|
Secunia Advisory ID |
SA105738 |
|
Creation Date |
2021-12-18 |
|
Criticality |
Less critical |
|
Zero Day |
No |
|
Impact |
Privilege escalation |
|
Where |
Local system |
|
Solution Status |
Vendor Patched |
|
Secunia CVSS Scores |
CVSS3 Base: 7.8, Overall: 6.8 |
|
CVE References |
CVE-2021-41526 |
Related Articles
Flexera product CVE reference list (November 2025 update) 15Number of Views CVE-2026-4869: Potential Privilege Escalation in InstallShield 2025 R2 running Setup Prerequisites from an insecure directory 8Number of Views CVE-2025-15467 Impact Assessment for FlexNet Embedded 6Number of Views CVE-2025-12418: Potential Unintended File Deletion Issue Caused by InstallShield Suite Uninstallation Process 10Number of Views Configuring Safety Relevance Metadata Using Custom Fields and CycloneDX Export in FlexNet Code Insight 20Number of Views
Hi, I am Reva - Ask me anything.
No new updates
Thanks for the feedback!
Your feedback has been saved.Rate this response:
Add Additional feedback ( Optional )
Are you sure you want to cancel
the case creation?
Are you sure you want to cancel the case creation?
Are you sure you want to close this case
| Products | Region | Phone Numbers |
|---|---|---|
| FlexNet Operations FlexNet Embedded FlexNet Publisher FlexNet Connect FlexNet Code Insight InstallAnywhere InstallShield |
North America * |
+1 630-332-2513 (toll) +1 877-279-2853 (toll-free in North America) |
| Europe * |
+44 1925 944367 (toll) +44 800 047 8642 (toll-free in Europe) |
|
| Japan * | +81 3-4540-5335 (select option 2) | |
| Australia * |
+61 3 9895 2177 +61 1800 560 603 (toll-free in Australia) |
|
|
Usage Intelligence (formerly
Revulytics) Compliance Intelligence |
Please use the Case Portal to submit your support ticket or reach out to your Revenera contact. | |
Revenera Assistant
Case id: 00001065
Activity: Status change: 2 hours ago