Creation of Temporary File With Insecure Permissions in InstallShield - CVE-2023-29080
Published: May 4, 2023
InstallShield
Macrovision Corporation
Description
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to an InstallScript custom action, added to a Basic MSI or InstallScript MSI project, extracts few binaries to a predefined writable folder during installation time. A local user can overwrite the files and execute arbitrary code with elevated privileges.