CVE-2017-20051

Summary

A vulnerability was detected in InnoSetup Installer 5.5.9. This affects an unknown part. The manipulation results in uncontrolled search path. The attack can be executed remotely. The exploit is now public and may be used. This is a malformed-PE / self-extracting-installer defect report that the vendor never acknowledged.

Affected Software

VendorProductVersion RangeStatus
InnoSetupInstaller5.5.9affected

Weaknesses

  • CWE-427: Uncontrolled Search Path
  • CWE-426: Untrusted Search Path

ADP Enrichment

CVE Program Container

Additional References

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: poc
    • Automatable: no
    • Technical Impact: partial

References