PT-2022-7924 · Unknown · Innosetup Installer

Stefan Kanthak

·

Published

2022-06-16

·

Updated

2022-06-27

·

CVE-2017-20051

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions InnoSetup Installer (affected versions not specified)
Description A vulnerability was found in the software, affecting an unknown functionality, which leads to an uncontrolled search path. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Uncontrolled Search Path Element

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-20051

Affected Products

Innosetup Installer