Local privilege escalation via writable DLL extraction
Published Jan 30, 2025 · Updated Feb 12, 2025
DLL hijacking in Revenera InstallShield 2021 R2 and 2022 R2 allows local users to gain elevated privileges during installation. InstallScript custom actions in Basic MSI or InstallScript MSI projects extract binaries to a predefined directory that standard users can write, allowing replacement before a privileged process loads them. Exploitation requires local standard-user access and an affected installer execution, after which attacker-controlled DLL code runs with the installer's elevated privileges.
Summary
What happened
DLL hijacking in Revenera InstallShield 2021 R2 and 2022 R2 allows local users to gain elevated privileges during installation. InstallScript custom actions in Basic MSI or InstallScript MSI projects extract binaries to a predefined directory that standard users can write, allowing replacement before a privileged process loads them. Exploitation requires local standard-user access and an affected installer execution, after which attacker-controlled DLL code runs with the installer's elevated privileges.
The record
- CVE
- CVE-2023-29080
- Published
- Jan 30, 2025
- Updated
- Feb 12, 2025
- Vendor
- Revenera
- Product
- InstallShield
- Classifications
- T1574.001
- Attack vector
- local
- Privileges
- authenticated
Timeline
How it unfolded
- Jan 30, 2025CVE publishedPublication date reported by the CVE source.
- Feb 12, 2025Record updatedLatest update available in the CVE record.
Exploitability
Present is not the same as exploitable
Compare your product and version with the public record. A matching version still requires validation against your environment.
Is a vulnerable build present?
Compare these published version ranges with your installed build and any vendor patches.
- Affected versionversion=2021 R2 <2021 R2 (27.0.0.126) changes=[{"at":"InstallShield 2021 R2 Security Patch (27.0.0.126)","status":"unaffected"}]
- Affected versionversion=2022 R2 <2022 R2 (28.0.0.763) changes=[{"at":"InstallShield 2022 R2 Security Patch (28.0.0.763)","status":"unaffected"}]
What conditions does exploitation require?
What is affected?
Published CVSS scores
No CVSS assessment is available in this record.
CVSS describes severity. EPSS estimates exploitation probability.
Attacks
What attackers are doing with it
Daily unique IPs observed by Shadowserver honeypots for known exploited vulnerabilities (KEVs). Missing observations do not establish an absence of attacks.
Weakness, pattern, technique
Public exploit references
No public exploit references are available in this record.
Labels summarize the accepted research assessment. They do not indicate a test against your environment.
Technologies
Your stack
See the directory against your own environment.
Your stack
Check the software in your environment
Book a demo to see how Hinoki identifies affected software and validates exploitability in your environment.
Book a demo