PT-2016-6020 · Flexera · Flexera Installanywhere

Published

2016-07-02

·

Updated

2016-11-28

·

CVE-2016-4560

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Flexera InstallAnywhere (affected versions not specified)
Description The issue is related to an untrusted search path vulnerability. It allows local users to gain privileges by using a Trojan horse DLL in the current working directory of a setup-launcher executable file.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2016-4560

Affected Products

Flexera Installanywhere