Summary
A vulnerability has been reported in the Basic MSI and InstallScript MSI (64-bit) Setups if configured with the options below:
- The project has Folder and Registry Permissions configured using 'Locked-Down Permissions' option set to 'Custom InstallShield handling'
- The Self-register option is configured with 'InstallShield Self-Registration table (ISSelfReg)'
Note: All supported versions (InstallShield 2023 R2, InstallShield 2022 R2 and InstallShield 2021 R2) are affected by this issue.
This article provides details about this potential vulnerability and the remediation steps available.
Description
There is known issue with Windows installer repair that allows a standard user to run MSI repair operations (performed by deferred CA) in NT AUTHORITY\SYSTEM context without requiring administrator credentials. This exploitable nature of MSI repair can present a potential security risk if the file operations from the deferred custom actions are not properly protected from standard user access.
If custom handling option is configured, InstallShield extracts an executable named ISBEW64.exe to the writable TEMP folder, which is used to perform additional tasks like setting file and registry permissions and self-registration of COM servers. This misconfiguration of extracting an executable file to a writable folder along with the MSI repair exploitable behavior could potentially lead to a local privilege escalation by replacing ISBEW64.EXE with a malicious one.
Workaround
The following workaround options are available to remediate this issue:
- Set 'Locked-Down Permissions' option to 'Traditional Windows Installer handling' or,
- Choose 'Windows Installer Self-Registration table (SelfReg)' option
Click the links above for more information about each option.
Fix Version and Resolution
A hotfix for InstallShield 2023 R2 is available for download here: InstallShield MSI Repair-Privilege Escalation using Custom Handling Hotfix
Additional Information
Thank you to Kravets Vasiliy for identifying this issue and disclosing it to Revenera.
Related Articles
CVE-2024-7562: Privilege Escalation Vulnerability in Created MSI Packages 127Number of Views CVE-2023-29080: Security patch for the possible privileged escalation scenarios identified in InstallShield 11Number of Views CVE-2026-4869: Potential Privilege Escalation in InstallShield 2025 R2 running Setup Prerequisites from an insecure directory 4Number of Views CVE-2024-2658: FlexNet Publisher potential local privilege escalation issue 15Number of Views The InstallAnywhere was created with Unlicensed version 8Number of Views
Hi, I am Reva - Ask me anything.
No new updates
Thanks for the feedback!
Your feedback has been saved.Rate this response:
Add Additional feedback ( Optional )
Are you sure you want to cancel
the case creation?
Are you sure you want to cancel the case creation?
Are you sure you want to close this case
| Products | Region | Phone Numbers |
|---|---|---|
| FlexNet Operations FlexNet Embedded FlexNet Publisher FlexNet Connect FlexNet Code Insight InstallAnywhere InstallShield |
North America * |
+1 630-332-2513 (toll) +1 877-279-2853 (toll-free in North America) |
| Europe * |
+44 1925 944367 (toll) +44 800 047 8642 (toll-free in Europe) |
|
| Japan * | +81 3-4540-5335 (select option 2) | |
| Australia * |
+61 3 9895 2177 +61 1800 560 603 (toll-free in Australia) |
|
|
Usage Intelligence (formerly
Revulytics) Compliance Intelligence |
Please use the Case Portal to submit your support ticket or reach out to your Revenera contact. | |
Case id: 00001065
Activity: Status change: 2 hours ago