CVE-2024-7562 HIGH

CVE-2024-7562

Vendor Revenera
Product InstallShield
Weakness CWE-379
Published June 12, 2025
Last update June 17, 2025

CVSS base score

7.3/10
Attack vector Local
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

What the vulnerability does

01Description

A potential elevated privilege issue has been reported with InstallShield built Standalone MSI setups having multiple InstallScript custom actions configured. All supported versions (InstallShield 2023 R2, InstallShield 2022 R2 and InstallShield 2021 R2) are affected by this issue.

Key dates

02Disclosure timeline

June 12, 2025 CVE published
June 17, 2025 Record updated