Description
Potential Denial of Service issue in all supported versions of Revenera InstallShield version 2025 R1, 2024 R2, 2023 R2, and prior. When e.g., a local administrator performs an uninstall, a symlink may get followed on removal of a user writeable configuration directory and induce a Denial of Service as a result. The issue is resolved through the hotfixes InstallShield2025R1-CVE-2025-12418-SecurityPatch, InstallShield2024R2-CVE-2025-12418-SecurityPatch, and InstallShield2023R2-CVE-2025-12418-SecurityPatch.
Problem types
CWE-59 Improper Link Resolution Before File Access ('Link Following')
Product status
2023.R1 (semver)
2024.R1 (semver)
2025.R1 (custom) before InstallShield2025R1-CVE-2025-12418-SecurityPatch
References
community.revenera.com/...hield-Suite-Uninstallation-Process