CVE-2023-29080 - CVE House
Back to Database
Status published High CVE-2023-29080

Privilege escalation in InstallShield

Vulnerability Description

Potential privilege escalation vulnerability in Revenera InstallShield versions 2022 R2 and 2021 R2 due to adding InstallScript custom action to a Basic MSI or InstallScript MSI project extracting few binaries to a predefined writable folder during installation time. The standard user account has write access to these files and folders, hence replacing them during installation time can lead to a DLL hijacking vulnerability.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-29080

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

InstallShield
Vulnerable Versions:
2022 R2, 2021 R2

Timeline

Official Publish: January 30th, 2025
Last Modified: February 12th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)