Windows Installer Uninstaller Vulnerability in a Major Software Suite
CVE-2021-22038
Summary
A security vulnerability exists in the uninstaller of Windows installers which improperly manages temporary file execution. When the uninstaller is activated, it duplicates itself to a predictable temporary directory that is not only accessible to non-Administrator users but also lacks sufficient protections. This design flaw allows an attacker to replace the uninstaller's binary with a malicious payload prior to execution, which could lead to unauthorized access and escalated privileges if the original uninstaller operates with Administrator rights. The vulnerability specifically impacts installers built on Windows systems.
Affected Version(s)
VMware InstallBuilder All InstallBuilder versions prior to version 21.6.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved