PT-2016-3439 · Flexera+1 · Flexera Installshield+1
Published
2016-02-24
·
Updated
2025-12-05
·
CVE-2016-2542
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Flexera InstallShield through 2015 SP1
AVEVA Edge InstallShield (affected versions not specified)
Description
The issue is related to an untrusted search path vulnerability that allows local users to gain privileges via a Trojan horse DLL in the current working directory of a setup-launcher executable file. It is also associated with the possibility of substituting a dynamic library, which can allow an attacker to execute arbitrary code or elevate their privileges.
Recommendations
For Flexera InstallShield through 2015 SP1: Update to a version later than 2015 SP1 to resolve the issue.
For AVEVA Edge InstallShield: At the moment, there is no information about a newer version that contains a fix for this vulnerability.
RCE
Uncontrolled Search Path Element
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Aveva Edge Installshield
Flexera Installshield