Privilege Escalation Vulnerability in InstallShield by Revenera
CVE-2024-7562

7.3HIGH

Key Information:

Vendor

Revenera

Vendor
CVE Published:
12 June 2025

What is CVE-2024-7562?

A privilege escalation vulnerability has been identified in InstallShield products, specifically affecting standalone MSI setups configured with multiple InstallScript custom actions. This vulnerability may allow unauthorized users to gain elevated privileges, potentially leading to unauthorized access to system resources. Users of InstallShield versions 2021 R2, 2022 R2, and 2023 R2 are strongly advised to review their configurations and apply necessary security measures to mitigate the risk associated with improper access controls in their MSI packages.

Affected Version(s)

InstallShield 2023 R2

InstallShield 2022 R2

InstallShield 2021 R2

References

CVSS V4

Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Sandro Poppi
.