Summary
An issue has been identified with the Suite installer’s uninstall process unintentionally deleting target files and folders associated with a symbolic link.
Description
The InstallShield update utility doesn't verify and removes potential symbolic link targets within a user writeable configuration directory on uninstall. This can result in a Denial of Service if e.g., an uninstall is triggered by an administrative user where the uninstaller accesses a configuration directory containing a specially crafted symbolic link.
The preliminary CVSS for this issue: CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H (5.6 score)
Resolution
A hotfix to address this issue is available for download from the Product and License Center. The hotfix will be available for the supported versions of InstallShield, which at the time this article is publish, includes InstallShield 2025 R1, InstallShield 2024 R2, and InstallShield 2023 R2.
Related Articles
Build Errors Caused By Windows Installer CAB File Format Limitations 3Number of Views Resolve User Console uninstallation error “Error Code: 9” caused by running Ux Service process 6Number of Views Issues caused by multiple Batch Processors. 7Number of Views Known Issue: Business adapter may fail to read data from CSV file if the "Column delimiter" setting is set to "semicolon" … 38Number of Views CVE-2024-14012: Potential Privilege Escalation in InstallShield 2023 R1 3Number of Views
Hi, I am Reva - Ask me anything.
No new updates
Thanks for the feedback!
Your feedback has been saved.Rate this response:
Add Additional feedback ( Optional )
Are you sure you want to cancel
the case creation?
Are you sure you want to cancel the case creation?
Are you sure you want to close this case
| Products | Region | Phone Numbers |
|---|---|---|
| FlexNet Operations FlexNet Embedded FlexNet Publisher FlexNet Connect FlexNet Code Insight InstallAnywhere InstallShield |
North America * |
+1 630-332-2513 (toll) +1 877-279-2853 (toll-free in North America) |
| Europe * |
+44 1925 944367 (toll) +44 800 047 8642 (toll-free in Europe) |
|
| Japan * | +81 3-4540-5335 (select option 2) | |
| Australia * |
+61 3 9895 2177 +61 1800 560 603 (toll-free in Australia) |
|
|
Usage Intelligence (formerly
Revulytics) Compliance Intelligence |
Please use the Case Portal to submit your support ticket or reach out to your Revenera contact. | |
Case id: 00001065
Activity: Status change: 2 hours ago