Path Interception Vulnerability in InstallBuilder Affects Windows Security
CVE-2021-22037
7.8HIGH
What is CVE-2021-22037?
The InstallBuilder software contains a vulnerability linked to the Windows registry manipulation process. By improperly controlling the execution path for the reg.exe command, the installer becomes susceptible to Path Interception via Search Order Hijacking. This flaw allows an attacker to potentially insert a malicious reg.exe command, enabling it to run with greater priority than the intended system command. Consequently, this can lead to unauthorized actions executed on affected Windows systems, compromising security.
Affected Version(s)
VMware InstallBuilder All InstallBuilder versions prior to version 21.6.0