PT-2021-4980 · Vmware · Vmware Installbuilder

Published

2021-10-19

·

Updated

2021-11-03

·

CVE-2021-22038

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions VMware InstallBuilder versions (affected versions not specified)
Description The issue is related to the use of insufficiently random values in the uninstaller binary of VMware InstallBuilder for Windows. When the uninstaller is executed, it copies itself to a fixed temporary location, which can be exploited by an attacker to gain Administrator privileges. This is possible because the temporary location is not randomized and does not restrict access to Administrators only, allowing a potential attacker to replace the copied binary with a malicious one. The vulnerability only affects Windows installers.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Use of Insufficiently Random Values

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-05740
CVE-2021-22038

Affected Products

Vmware Installbuilder