{"dataType":"CVE_RECORD","dataVersion":"5.1","cveMetadata":{"state":"PUBLISHED","cveId":"CVE-2021-41526","assignerOrgId":"44d08088-2bea-4760-83a6-1e9be26b15ab","assignerShortName":"flexera","dateUpdated":"2024-08-04T03:15:28.449Z","dateReserved":"2021-09-20T00:00:00.000Z","datePublished":"2023-03-29T00:00:00.000Z"},"containers":{"cna":{"providerMetadata":{"orgId":"44d08088-2bea-4760-83a6-1e9be26b15ab","shortName":"flexera","dateUpdated":"2024-04-19T15:05:51.662Z"},"descriptions":[{"lang":"en","value":"A vulnerability has been reported in the windows installer (MSI) built with InstallScript custom action. This vulnerability may allow privilege escalation when invoked ‘repair’ of the MSI which has an InstallScript custom action."}],"affected":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}],"references":[{"url":"https://community.flexera.com/t5/InstallShield-Knowledge-Base/CVE-2021-41526-Privilege-escalation-vulnerability-during-MSI/ta-p/218137/jump-to/first-unread-message"},{"url":"https://github.com/mandiant/Vulnerability-Disclosures/blob/master/MNDT-2021-0011/MNDT-2021-0011.md"},{"name":"20240419 MindManager 23 - full disclosure","tags":["mailing-list"],"url":"http://seclists.org/fulldisclosure/2024/Apr/24"}],"problemTypes":[{"descriptions":[{"type":"text","lang":"en","description":"n/a"}]}]},"adp":[{"affected":[{"vendor":"flexera","product":"revenera_installshield","cpes":["cpe:2.3:a:flexera:revenera_installshield:-:*:*:*:*:windows:*:*"],"defaultStatus":"unknown","versions":[{"version":"0","status":"affected","lessThan":"2021","versionType":"custom"}]},{"vendor":"flexera","product":"revenera_installshield","cpes":["cpe:2.3:a:flexera:revenera_installshield:2021:-:*:*:*:windows:*:*"],"defaultStatus":"unknown","versions":[{"version":"2021","status":"affected"}]},{"vendor":"flexera","product":"revenera_installshield","cpes":["cpe:2.3:a:flexera:revenera_installshield:2021:r1:*:*:*:windows:*:*"],"defaultStatus":"unknown","versions":[{"version":"2021","status":"affected"}]}],"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2024-07-24T14:30:28.705266Z","id":"CVE-2021-41526","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2024-07-24T14:33:52.948Z"}},{"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2024-08-04T03:15:28.449Z"},"title":"CVE Program Container","references":[{"url":"https://community.flexera.com/t5/InstallShield-Knowledge-Base/CVE-2021-41526-Privilege-escalation-vulnerability-during-MSI/ta-p/218137/jump-to/first-unread-message","tags":["x_transferred"]},{"url":"https://github.com/mandiant/Vulnerability-Disclosures/blob/master/MNDT-2021-0011/MNDT-2021-0011.md","tags":["x_transferred"]},{"name":"20240419 MindManager 23 - full disclosure","tags":["mailing-list","x_transferred"],"url":"http://seclists.org/fulldisclosure/2024/Apr/24"}]}]}}