Path Interception Vulnerability in InstallBuilder Affects Windows Security
CVE-2021-22037
7.8HIGH
Summary
The InstallBuilder software contains a vulnerability linked to the Windows registry manipulation process. By improperly controlling the execution path for the reg.exe command, the installer becomes susceptible to Path Interception via Search Order Hijacking. This flaw allows an attacker to potentially insert a malicious reg.exe command, enabling it to run with greater priority than the intended system command. Consequently, this can lead to unauthorized actions executed on affected Windows systems, compromising security.
Affected Version(s)
VMware InstallBuilder All InstallBuilder versions prior to version 21.6.0
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved