PT-2016-3439 · Flexera+1 · Flexera Installshield+1

Published

2016-02-24

·

Updated

2025-12-05

·

CVE-2016-2542

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Flexera InstallShield through 2015 SP1 AVEVA Edge InstallShield (affected versions not specified)
Description The issue is related to an untrusted search path vulnerability that allows local users to gain privileges via a Trojan horse DLL in the current working directory of a setup-launcher executable file. It is also associated with the possibility of substituting a dynamic library, which can allow an attacker to execute arbitrary code or elevate their privileges.
Recommendations For Flexera InstallShield through 2015 SP1: Update to a version later than 2015 SP1 to resolve the issue. For AVEVA Edge InstallShield: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Uncontrolled Search Path Element

Weakness Enumeration

Related Identifiers

BDU:2022-07235
CVE-2016-2542

Affected Products

Aveva Edge Installshield
Flexera Installshield