Aller au contenu

Fiche vulnérabilité

CVE-2021-22038 : faille élevée vmware installbuilder (CVSS 8.8)

Description

On Windows, the uninstaller binary copies itself to a fixed temporary location, which is then executed (the originally called uninstaller exits, so it does not block the installation directory). This temporary location is not randomized and does not restrict access to Administrators only so a potential attacker could plant a binary to replace the copied binary right before it gets called, thus gaining Administrator privileges (if the original uninstaller was executed as Administrator). The vulnerability only affects Windows installers.

En bref

Sévérité
Élevée (CVSS 8.8)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
29 oct. 2021
Dernière mise à jour
17 juin 2026

Produits concernés

  • vmware installbuilder

Références

Rechercher une autre vulnérabilité dans la base CVE