Entreprise d'experts en Sécurité Informatique : Audits et conseils en cybersécurité
Entreprise française de cybersécurité depuis 2004
☎ 03 60 47 09 81 - info@securiteinfo.com


CVE-2021-41526

Description

A vulnerability has been reported in the windows installer (MSI) built with InstallScript custom action. This vulnerability may allow privilege escalation when invoked ‘repair’ of the MSI which has an InstallScript custom action.

POC

Reference

- http://seclists.org/fulldisclosure/2024/Apr/24

Github

- https://github.com/RonnieSalomonsen/My-CVEs

- https://github.com/pawlokk/mindmanager-poc